Описание
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss A-MQ 6 | shiro-core | Not affected | ||
| Red Hat JBoss Fuse 6 | shiro-core | Not affected | ||
| Red Hat JBoss Fuse Service Works 6.0 | shiro-web | Affected | ||
| Red Hat OpenShift Enterprise 2 | shiro-core | Affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1375884Shiro: Security servlet filters bypass
EPSS
Процентиль: 94%
0.13506
Средний
5.6 Medium
CVSS3
6.8 Medium
CVSS2
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 9 лет назад
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
CVSS3: 7.5
nvd
больше 9 лет назад
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
CVSS3: 7.5
debian
больше 9 лет назад
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet ...
EPSS
Процентиль: 94%
0.13506
Средний
5.6 Medium
CVSS3
6.8 Medium
CVSS2