Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1957

Опубликовано: 25 мар. 2020
Источник: redhat
CVSS3: 9.8
EPSS Высокий

Описание

Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

A flaw was found in Apache Shiro. When using Spring dynamic controllers, a specially crafted request may cause an authentication bypass. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

Whilst the OpenDaylight version that is included in Red Hat OpenStack Platform includes the affected code, the vulnerable function is not used and therefore not exploitable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7shiro-coreNot affected
Red Hat JBoss A-MQ 6shiro-coreNot affected
Red Hat JBoss Fuse 6shiro-coreNot affected
Red Hat JBoss Fuse Service Works 6shiro-coreNot affected
Red Hat OpenStack Platform 10 (Newton)opendaylightWill not fix
Red Hat OpenStack Platform 13 (Queens)opendaylightWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1829281shiro: Spring dynamic controllers, a specially crafted request may cause an authentication bypass

EPSS

Процентиль: 99%
0.86102
Высокий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

CVSS3: 9.8
nvd
больше 5 лет назад

Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

CVSS3: 9.8
debian
больше 5 лет назад

Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic ...

CVSS3: 9.8
github
больше 4 лет назад

Improper Authentication in Apache Shiro

EPSS

Процентиль: 99%
0.86102
Высокий

9.8 Critical

CVSS3