Lucene search

K
broadcomBroadcom Security ResponseBSNSA23256
HistoryApr 16, 2024 - 12:00 a.m.

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack (CVE-2023-34478)

2024-04-1600:00:00
Broadcom Security Response
support.broadcom.com
8
apache shiro
path traversal
vulnerability
authentication bypass
update
software

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

40.9%

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+

Affected configurations

Vulners
Node
broadcombrocade_sannavRange<2.3.1
CPENameOperatorVersion
brocade sannavlt2.3.1

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

40.9%