Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p836-389h-j692

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Improper Access Control in Apache Shiro

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

Пакеты

Наименование

org.apache.shiro:shiro-core

maven
Затронутые версииВерсия исправления

<= 1.2.4

1.2.5

EPSS

Процентиль: 100%
0.94214
Критический

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-321

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

CVSS3: 7.3
redhat
больше 9 лет назад

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

CVSS3: 9.8
nvd
больше 9 лет назад

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

CVSS3: 9.8
debian
больше 9 лет назад

Apache Shiro before 1.2.5, when a cipher key has not been configured f ...

EPSS

Процентиль: 100%
0.94214
Критический

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-321