Lucene search

K
cvelistApacheCVELIST:CVE-2023-34478
HistoryJul 24, 2023 - 6:24 p.m.

CVE-2023-34478 Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.

2023-07-2418:24:45
CWE-22
apache
www.cve.org
1
vulnerability
apache shiro
path traversal
authentication bypass
mitigation

9.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.9%

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.

Mitigation:Β Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache Shiro",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "1.12.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      },
      {
        "lessThan": "2.0.0-alpha-3",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

9.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.9%