Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-11989

Опубликовано: 22 июн. 2020
Источник: redhat
CVSS3: 9.8

Описание

Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

A flaw was found in Apache Shiro in versions prior to 1.5.3. When using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

Whilst the OpenDaylight version that is included in Red Hat OpenStack Platform includes the affected code, the vulnerable functionality is not used and therefore not exploitable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6shiro-coreNot affected
Red Hat JBoss Fuse 6shiro-coreNot affected
Red Hat JBoss Fuse Service Works 6shiro-coreOut of support scope
Red Hat OpenStack Platform 10 (Newton)opendaylightOut of support scope
Red Hat OpenStack Platform 13 (Queens)opendaylightWill not fix
Red Hat Fuse 7.8.0shiro-coreFixedRHSA-2020:556816.12.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=1850069shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

CVSS3: 9.8
nvd
больше 5 лет назад

Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

CVSS3: 9.8
debian
больше 5 лет назад

Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic ...

CVSS3: 9.8
github
больше 4 лет назад

Improper Authentication in Apache Shiro

9.8 Critical

CVSS3