Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-68497
HistoryOct 13, 2022 - 12:00 a.m.

Apache Shiro Authentication Bypass Vulnerability (CNVD-2022-68497)

2022-10-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
18
java
security framework
authentication
access authorization
data encryption
session management
apache shiro
vulnerability
requestdispatcher interface

0.007 Low

EPSS

Percentile

81.0%

Apache Shiro is a Java security framework with authentication, access authorization, data encryption, session management, etc. An authentication bypass vulnerability exists in Apache Shiro, which is caused when requests are forwarded or requests are included via the RequestDispatcher interface, and no details of the vulnerability are currently available.

CPENameOperatorVersion
apache shiro <eq1.10.0