Apache Software Foundation Apache Shiro vulnerabilities

9 known vulnerabilities affecting apache_software_foundation/apache_shiro.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-23901LOWCVSS 1.0fixed in 2.0.72026-02-10
CVE-2026-23901 [LOW] CWE-208 CVE-2026-23901: Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue. Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough, that a brute-force attack may be able to tell, by timing
cvelistv5nvd
CVE-2026-23903MEDIUMCVSS 5.3fixed in 2.0.72026-02-09
CVE-2026-23903 [MEDIUM] CWE-289 CVE-2026-23903: Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Sh Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static files may be accesse
cvelistv5nvd
CVE-2023-46749MEDIUMCVSS 6.5fixed in 1.13.0≥ 2.0.0-alpha-1, < 2.0.0-alpha-42024-01-15
CVE-2023-46749 [MEDIUM] CWE-22 CVE-2023-46749: Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that resu Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon` is enabled (this is the default).
cvelistv5nvd
CVE-2023-46750MEDIUMCVSS 6.1fixed in 1.13.0≥ 2.0.0-alpha-1, < 2.0.0-alpha-42023-12-14
CVE-2023-46750 [MEDIUM] CWE-601 CVE-2023-46750: URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
cvelistv5nvd
CVE-2023-34478CRITICALCVSS 9.8fixed in 1.12.0fixed in 2.0.0-alpha-32023-07-24
CVE-2023-34478 [CRITICAL] CWE-22 CVE-2023-34478: Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that res Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+
cvelistv5nvd
CVE-2022-40664CRITICALCVSS 9.8≥ Apache Shiro, < 1.10.02022-10-12
CVE-2022-40664 [CRITICAL] CWE-287 CVE-2022-40664: Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or includin Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
cvelistv5nvd
CVE-2022-32532CRITICALCVSS 9.8vBefore 1.9.12022-06-29
CVE-2022-32532 [CRITICAL] CWE-863 CVE-2022-32532: Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
cvelistv5nvd
CVE-2021-41303CRITICALCVSS 9.8≥ Apache Shiro, < 1.8.02021-09-17
CVE-2021-41303 [CRITICAL] CWE-287 CVE-2021-41303: Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP reques Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
cvelistv5nvd
CVE-2020-11989CRITICALCVSS 9.8vApache Shiro 1.5.2 - 1.5.32020-06-22
CVE-2020-11989 [CRITICAL] CVE-2020-11989: Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially craf Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
cvelistv5nvd