Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2115 | Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+ |
Github GHSA |
GHSA-pmhc-2g4f-85cg | Path Traversal in Apache Shiro |
Ubuntu USN |
USN-7147-1 | Apache Shiro vulnerabilities |
Thu, 13 Feb 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+ | Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+ |
Wed, 02 Oct 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:55:37.269Z
Reserved: 2023-06-07T18:50:06.956Z
Link: CVE-2023-34478
Updated: 2024-08-02T16:10:07.042Z
Status : Modified
Published: 2023-07-24T19:15:10.630
Modified: 2025-02-13T17:16:38.883
Link: CVE-2023-34478
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN