cbcvebase.
CVE-2023-34478
published 2023-07-24

CVE-2023-34478: Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+

Affected

7 ranges
VendorProductVersion rangeFixed in
apacheshiro< 1.12.01.12.0
apacheshiro
apacheshiro>= 0 < 1.2.4-1ubuntu0.1~esm21.2.4-1ubuntu0.1~esm2
apacheshiro>= 0 < 1.3.2-5ubuntu0.24.04.1~esm11.3.2-5ubuntu0.24.04.1~esm1
apache_software_foundationapache_shiro< 1.12.01.12.0
apache_software_foundationapache_shiro< 2.0.0-alpha-32.0.0-alpha-3
debianshiro

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vulncheck9.8CRITICAL