Vulnerability Name: | CVE-2020-17523 (CCN-195875) | ||||||||||||
Assigned: | 2020-08-12 | ||||||||||||
Published: | 2021-02-01 | ||||||||||||
Updated: | 2022-02-22 | ||||||||||||
Summary: | Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C)
| ||||||||||||
Vulnerability Type: | CWE-287 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-17523 Source: XF Type: UNKNOWN apache-cve202017523-sec-bypass(195875) Source: MLIST Type: Mailing List, Vendor Advisory [activemq-gitbox] 20210210 [GitHub] [activemq] ehossack-aws opened a new pull request #614: Update shiro to 1.7.1 Source: MLIST Type: Mailing List, Vendor Advisory [shiro-dev] 20210424 Re: Ask help for upgrading Shiro in CDH platform to 1.7.1 Source: MLIST Type: Mailing List, Vendor Advisory [activemq-users] 20210427 Release date for ActiveMQ v5.16.2 to fix CVEs Source: MLIST Type: Mailing List, Vendor Advisory [shiro-dev] 20210504 Re: Request for assistance to backport CVE-2020-13933 fix Source: MLIST Type: Mailing List, Vendor Advisory [shiro-dev] 20210331 Re: Request for assistance to backport CVE-2020-13933 fix Source: MISC Type: Mailing List, Vendor Advisory https://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org%3E Source: MLIST Type: Mailing List, Vendor Advisory [activemq-issues] 20210301 [jira] [Created] (AMQ-8159) High severity security issues found in Apache Shiro v.1.7.0 Source: MLIST Type: Mailing List, Vendor Advisory [shiro-dev] 20210407 Re: Request for assistance to backport CVE-2020-13933 fix Source: CCN Type: oss-sec Mailing List, Mon, 1 Feb 2021 11:07:59 -0500 [CVE-2020-17523] Apache Shiro authentication bypass Source: CCN Type: Apache Web site Apache Shiro Source: CCN Type: IBM Security Bulletin 6491163 (Planning Analytics) IBM Planning Analytics Workspace is affected by security vulnerabilities | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |