PT-2026-52220 · Apache · Apache Shiro
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:D/RE:L/U:Amber |
Name of the Vulnerable Software and Affected Versions
Apache Shiro versions prior to 3.0.0
Description
When using the
shiro-guice module within a web servlet context, a specially crafted HTTP request can lead to an authentication bypass. This allows an attacker to circumvent security checks and gain unauthorized access to protected resources.Recommendations
Upgrade to version 3.0.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Shiro