PT-2016-3363 · Apache+1 · Apache Shiro+1
CVE-2016-4437
·
Publicado
2016-06-03
·
Atualizado
2026-09-07
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Shiro versions prior to 1.2.5
Description
The issue is related to the "remember me" feature in Apache Shiro, where the lack of a configured cipher key allows remote attackers to execute arbitrary code or bypass intended access restrictions. This can be achieved via an unspecified request parameter. The vulnerability is associated with the use of a default encryption key.
Recommendations
For versions prior to 1.2.5, update to version 1.2.5 or later to resolve the issue. As a temporary workaround, consider configuring a cipher key for the "remember me" feature to prevent exploitation. Restrict access to the "remember me" functionality until a patch is applied.
Exploit
Correção
RCE
Improper Authentication
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Shiro
Ubuntu