CVE-2023-34478
published 2023-07-24CVE-2023-34478: Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with…
PriorityP183critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.53%
72.0th percentile
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.
Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | < 1.12.0 | 1.12.0 |
| apache | shiro | — | — |
| apache | shiro | >= 0 < 1.2.4-1ubuntu0.1~esm2 | 1.2.4-1ubuntu0.1~esm2 |
| apache | shiro | >= 0 < 1.3.2-5ubuntu0.24.04.1~esm1 | 1.3.2-5ubuntu0.24.04.1~esm1 |
| apache_software_foundation | apache_shiro | < 1.12.0 | 1.12.0 |
| apache_software_foundation | apache_shiro | < 2.0.0-alpha-3 | 2.0.0-alpha-3 |
| debian | shiro | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for path traversal patterns in HTTP request paths targeting Apache Shiro-protected endpoints — non-normalized URLs (e.g., containing `/../`, `%2F..`, `%2e%2e`) may bypass authentication checks when Shiro is used alongside other web frameworks or path-rewriting APIs. ↗
- →Monitor for requests that reach protected resources without proper authentication, particularly where the upstream framework normalizes the path differently than Shiro — discrepancies between raw and normalized request paths are a key indicator. ↗
- ·Vulnerability only manifests when Apache Shiro is deployed together with other web frameworks or APIs that route based on non-normalized request paths — standalone Shiro deployments are not affected in the same way. ↗
- ·Affected versions are Apache Shiro before 1.12.0 (1.x branch) or before 2.0.0-alpha-3 (2.x branch); detection/patching scope should cover both version lines. ↗
- ·Debian (bookworm, bullseye, sid, trixie) packages remain open/unpatched as of the tracker entry — environments using Debian-packaged Shiro should be treated as unmitigated. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vulncheck9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Shiro vulnerabilities
vendor_ubuntu·2024-12-10·CVSS 7.5
CVE-2023-34478 [HIGH] Apache Shiro vulnerabilities
Title: Apache Shiro vulnerabilities
Summary: Several security issues were fixed in Apache Shiro.
It was discovered that Apache Shiro incorrectly handled path traversal when
used with other web frameworks or path rewriting. An attacker could
possibly use this issue to obtain sensitive information or administrative
privileges. This update provides the corresponding fix for Ubuntu 24.04 LTS
and Ubuntu 24.10. (CVE-2023-34478, CVE-2023-46749)
It was discovered that Apache Shiro incorrectly handled web redirects when
used together with the form authentication method. An attacker could
possibly use this issue to perform phishing attacks. This update provides
the corresponding fix for Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2023-46750)
It was discovered that Apache Shiro incorrectly handled re
Debian
CVE-2023-34478: shiro - Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path trave...
vendor_debian·2023·CVSS 9.8
CVE-2023-34478 [CRITICAL] CVE-2023-34478: shiro - Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path trave...
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+
Scope: local
bookworm: open
bullseye: open
sid: open
trixie: open
OSV
shiro vulnerabilities
osv·2024-12-10·CVSS 7.5
CVE-2023-34478 [HIGH] shiro vulnerabilities
shiro vulnerabilities
It was discovered that Apache Shiro incorrectly handled path traversal when
used with other web frameworks or path rewriting. An attacker could
possibly use this issue to obtain sensitive information or administrative
privileges. This update provides the corresponding fix for Ubuntu 24.04 LTS
and Ubuntu 24.10. (CVE-2023-34478, CVE-2023-46749)
It was discovered that Apache Shiro incorrectly handled web redirects when
used together with the form authentication method. An attacker could
possibly use this issue to perform phishing attacks. This update provides
the corresponding fix for Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2023-46750)
It was discovered that Apache Shiro incorrectly handled requests through
servlet filtering. An attacker could possibly use this issue
OSV
CVE-2023-34478: Apache Shiro, before 1
osv·2023-07-24·CVSS 9.8
CVE-2023-34478 [CRITICAL] CVE-2023-34478: Apache Shiro, before 1
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+
GHSA
Path Traversal in Apache Shiro
ghsa·2023-07-24
CVE-2023-34478 [CRITICAL] CWE-22 Path Traversal in Apache Shiro
Path Traversal in Apache Shiro
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.
Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+
OSV
Path Traversal in Apache Shiro
osv·2023-07-24
CVE-2023-34478 [CRITICAL] Path Traversal in Apache Shiro
Path Traversal in Apache Shiro
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.
Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+
VulnCheck
Apache Shiro Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2023·CVSS 9.8
CVE-2023-34478 [CRITICAL] Apache Shiro Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Apache Shiro Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.
Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+
Affected: Apache Shiro
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://sosintel.co.uk/flash-alert-cves-of-note-being-exploited-in-the-wild/
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/07/24/4https://lists.apache.org/thread/mbv26onkgw9o35rldh7vmq11wpv2t2qkhttps://security.netapp.com/advisory/ntap-20230915-0005/http://www.openwall.com/lists/oss-security/2023/07/24/4https://lists.apache.org/thread/mbv26onkgw9o35rldh7vmq11wpv2t2qkhttps://security.netapp.com/advisory/ntap-20230915-0005/
2023-07-24
Published
Exploited in the wild