Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-17510

Опубликовано: 05 нояб. 2020
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

A flaw was found in Apache shiro. When using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. This highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

Whilst the OpenDaylight version that is included in Red Hat OpenStack Platform includes the affected code, the vulnerable function is not used and therefore not exploitable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Integration Camel K 1camel-shiroNot affected
Red Hat JBoss A-MQ 6shiroOut of support scope
Red Hat JBoss Fuse 6shiro-coreOut of support scope
Red Hat JBoss Fuse Service Works 6shiro-coreNot affected
Red Hat OpenStack Platform 10 (Newton)opendaylightOut of support scope
Red Hat OpenStack Platform 13 (Queens)opendaylightWill not fix
Red Hat Fuse 7.9shiro-coreFixedRHSA-2021:314011.08.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=1903727shiro: specially crafted HTTP request may cause an authentication bypass

EPSS

Процентиль: 82%
0.01799
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

CVSS3: 9.8
nvd
больше 5 лет назад

Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

CVSS3: 9.8
debian
больше 5 лет назад

Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a spec ...

CVSS3: 9.8
github
почти 5 лет назад

Authentication bypass in Apache Shiro

CVSS3: 9.8
fstec
больше 5 лет назад

Уязвимость фреймворка Apache Shiro , связанная с отсутствием процедуры аутентификации, позволяющая нарушителю загрузить специально созданный вредоносный файл

EPSS

Процентиль: 82%
0.01799
Низкий

9.8 Critical

CVSS3