Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-17523

Опубликовано: 01 янв. 2021
Источник: redhat
CVSS3: 9.8

Описание

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

A flaw was found in Apache Shiro. When using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. The highest threat from this vulnerability is to data confidentiality, integrity as well as system availability.

Отчет

Although Red Hat OpenStack Platform's OpenDaylight includes the affected code, the vulnerable function is not used and therefore not exploitable. For this reason, the RHOSP impact is low and no update will be provided at this time for OpenDaylight.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7shiro-coreWill not fix
Red Hat JBoss A-MQ 6shiro-coreOut of support scope
Red Hat JBoss Fuse 6shiro-coreOut of support scope
Red Hat OpenStack Platform 10 (Newton)opendaylightOut of support scope
Red Hat OpenStack Platform 13 (Queens)opendaylightWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=1923838shiro: Authentication bypass through specially crafted HTTP request

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

CVSS3: 9.8
nvd
около 5 лет назад

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

CVSS3: 9.8
debian
около 5 лет назад

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a spec ...

CVSS3: 9.8
github
почти 4 года назад

Authentication bypass in Apache Shiro

CVSS3: 9.1
fstec
около 5 лет назад

Уязвимость фреймворка Apache Shiro, связанная с недостатками аутентификации, позволяющая нарушителю повысить свои привилегии

9.8 Critical

CVSS3