Описание
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss A-MQ 6 | shiro-core | Not affected | ||
| Red Hat JBoss Fuse 6 | shiro-core | Not affected | ||
| Red Hat JBoss Fuse Service Works 6 | shiro-web | Affected | ||
| Red Hat OpenShift Enterprise 2 | shiro-core | Affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1375884Shiro: Security servlet filters bypass
EPSS
Процентиль: 95%
0.0968
Низкий
5.6 Medium
CVSS3
6.8 Medium
CVSS2
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 10 лет назад
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
CVSS3: 7.5
nvd
почти 10 лет назад
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
CVSS3: 7.5
debian
почти 10 лет назад
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet ...
EPSS
Процентиль: 95%
0.0968
Низкий
5.6 Medium
CVSS3
6.8 Medium
CVSS2