Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-41303

Опубликовано: 16 сент. 2021
Источник: redhat
CVSS3: 9.8

Описание

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

A flaw was found in Apache Shiro. When using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. The highest threat from this vulnerability is to data confidentiality, integrity as well as system availability.

Отчет

Although Red Hat OpenStack Platform's OpenDaylight includes the affected code, the vulnerable function is not used, therefore, not exploitable. For this reason, the RHOSP impact is low, and no update will be provided at this time for OpenDaylight.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7shiro-webFix deferred
Red Hat JBoss A-MQ 6shiro-webOut of support scope
Red Hat JBoss Fuse 6shiro-webOut of support scope
Red Hat OpenStack Platform 10 (Newton)opendaylightOut of support scope
Red Hat OpenStack Platform 13 (Queens)opendaylightOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2006058shiro: specially crafted HTTP request may cause an authentication bypass

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

CVSS3: 9.8
nvd
больше 4 лет назад

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

CVSS3: 9.8
debian
больше 4 лет назад

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a ...

CVSS3: 9.8
github
больше 4 лет назад

Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость фреймворка Apache Shiro, связанная с недостатками механизма аутентификации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

9.8 Critical

CVSS3