Lucene search

K
debianDebianDEBIAN:DLA-2273-1:3F203
HistoryJul 08, 2020 - 2:55 p.m.

[SECURITY] [DLA 2273-1] shiro security update

2020-07-0814:55:57
lists.debian.org
15

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.016 Low

EPSS

Percentile

87.3%

Package : shiro
Version : 1.3.2-1+deb9u1
CVE IDs : CVE-2020-1957 CVE-2020-11989
Debian Bug : #955018

It was discovered that there was two issues in shiro, a security
framework for Java application:

  • CVE-2020-1957: Fix a path-traversal issue where a
    specially-crafted request could cause an authentication bypass.

  • CVE-2020-11989: Fix an encoding issue introduced in the handling
    of the previous CVE-2020-1957 path-traversal issue which itself
    could have also caused an authentication bypass.

For Debian 9 "Stretch", these issues have been fixed in shiro version
1.3.2-1+deb9u1.

We recommend that you upgrade your shiro packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

OSVersionArchitecturePackageVersionFilename
Debian9allshiro< 1.3.2-1+deb9u1shiro_1.3.2-1+deb9u1_all.deb
Debian9alllibshiro-java< 1.3.2-1+deb9u1libshiro-java_1.3.2-1+deb9u1_all.deb

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.016 Low

EPSS

Percentile

87.3%