CVE-2023-46749
published 2024-01-15CVE-2023-46749: Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with…
PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.18%
63.9th percentile
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting
Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon` is enabled (this is the default).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | < 1.13.0 | 1.13.0 |
| apache | shiro | — | — |
| apache | shiro | >= 0 < 1.3.2-4+deb11u1 | 1.3.2-4+deb11u1 |
| apache | shiro | >= 0 < 1.3.2-5 | 1.3.2-5 |
| apache | shiro | >= 0 < 1.3.2-5 | 1.3.2-5 |
| apache | shiro | >= 0 < 1.2.4-1ubuntu0.1~esm2 | 1.2.4-1ubuntu0.1~esm2 |
| apache | shiro | >= 0 < 1.3.2-5ubuntu0.24.04.1~esm1 | 1.3.2-5ubuntu0.24.04.1~esm1 |
| apache_software_foundation | apache_shiro | < 1.13.0 | 1.13.0 |
| apache_software_foundation | apache_shiro | >= 2.0.0-alpha-1 < 2.0.0-alpha-4 | 2.0.0-alpha-4 |
| debian | shiro | < shiro 1.3.2-5 (bookworm) | shiro 1.3.2-5 (bookworm) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Shiro vulnerabilities
vendor_ubuntu·2024-12-10·CVSS 7.5
CVE-2023-34478 [HIGH] Apache Shiro vulnerabilities
Title: Apache Shiro vulnerabilities
Summary: Several security issues were fixed in Apache Shiro.
It was discovered that Apache Shiro incorrectly handled path traversal when
used with other web frameworks or path rewriting. An attacker could
possibly use this issue to obtain sensitive information or administrative
privileges. This update provides the corresponding fix for Ubuntu 24.04 LTS
and Ubuntu 24.10. (CVE-2023-34478, CVE-2023-46749)
It was discovered that Apache Shiro incorrectly handled web redirects when
used together with the form authentication method. An attacker could
possibly use this issue to perform phishing attacks. This update provides
the corresponding fix for Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2023-46750)
It was discovered that Apache Shiro incorrectly handled re
Red Hat
shiro: path traversal attack may lead to authentication bypass
vendor_redhat·2024-01-12·CVSS 6.5
CVE-2023-46749 [MEDIUM] CWE-22 shiro: path traversal attack may lead to authentication bypass
shiro: path traversal attack may lead to authentication bypass
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting
Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon` is enabled (this is the default).
A flaw was found in Apache Shiro, which may allow a path traversal attack. When this issue is combined with the path rewriting feature, it can lead to an authentication bypass.
Mitigation: This flaw can be mitigated by making sure 'blockSemicolon' is enabled.
Package: shiro (Red Hat build of Apache Camel for Spring Boot 3) - Out of support scope
Package: shiro (Red Hat build of Apache Camel for Spring Boot 4) - Not affected
Package:
Debian
CVE-2023-46749: shiro - Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traver...
vendor_debian·2023·CVSS 6.5
CVE-2023-46749 [MEDIUM] CVE-2023-46749: shiro - Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traver...
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon` is enabled (this is the default).
Scope: local
bookworm: resolved (fixed in 1.3.2-5)
bullseye: resolved (fixed in 1.3.2-4+deb11u1)
sid: resolved (fixed in 1.3.2-5)
trixie: resolved (fixed in 1.3.2-5)
OSV
shiro vulnerabilities
osv·2024-12-10·CVSS 7.5
CVE-2023-34478 [HIGH] shiro vulnerabilities
shiro vulnerabilities
It was discovered that Apache Shiro incorrectly handled path traversal when
used with other web frameworks or path rewriting. An attacker could
possibly use this issue to obtain sensitive information or administrative
privileges. This update provides the corresponding fix for Ubuntu 24.04 LTS
and Ubuntu 24.10. (CVE-2023-34478, CVE-2023-46749)
It was discovered that Apache Shiro incorrectly handled web redirects when
used together with the form authentication method. An attacker could
possibly use this issue to perform phishing attacks. This update provides
the corresponding fix for Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2023-46750)
It was discovered that Apache Shiro incorrectly handled requests through
servlet filtering. An attacker could possibly use this issue
GHSA
Apache Shiro vulnerable to path traversal
ghsa·2024-01-15
CVE-2023-46749 [MEDIUM] CWE-22 Apache Shiro vulnerable to path traversal
Apache Shiro vulnerable to path traversal
Apache Shiro before 1.130 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting
Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon` is enabled (this is the default).
OSV
Apache Shiro vulnerable to path traversal
osv·2024-01-15
CVE-2023-46749 [MEDIUM] Apache Shiro vulnerable to path traversal
Apache Shiro vulnerable to path traversal
Apache Shiro before 1.130 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting
Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon` is enabled (this is the default).
OSV
CVE-2023-46749: Apache Shiro before 1
osv·2024-01-15·CVSS 6.5
CVE-2023-46749 [MEDIUM] CVE-2023-46749: Apache Shiro before 1
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon` is enabled (this is the default).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-46749 shiro: path traversal attack may lead to authentication bypass
bugzilla·2024-01-12·CVSS 6.5
CVE-2023-46749 [MEDIUM] CVE-2023-46749 shiro: path traversal attack may lead to authentication bypass
CVE-2023-46749 shiro: path traversal attack may lead to authentication bypass
Apache Shiro before 1.130 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting.
Discussion:
This issue has been addressed in the following products:
Red Hat Fuse 7.13.0
Via RHSA-2024:3354 https://access.redhat.com/errata/RHSA-2024:3354
Wiz
CVE-2026-23901 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-23901 [CRITICAL] CVE-2026-23901 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23901 :
Apache Shiro vulnerability analysis and mitigation
Observable Timing Discrepancy vulnerability in Apache Shiro.
This issue affects Apache Shiro: from 1. , 2. before 2.0.7.
Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue.
Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough,
that a brute-force attack may be able to tell, by timing the requests only, determine if
the request failed because of a non-existent user vs. wrong password.
The most likely attack vector is a local attack only.
Shiro security model https://shiro.apache.org/security-model.html#username_enumeration discusses this as well.
Typically, brute force attack can be mitigated at the infrastructure level.
Source : NVD
## 1
Scor
2024-01-15
Published