Lucene search

K
osvGoogleOSV:GHSA-72W9-FCJ5-3FCG
HistoryMay 07, 2021 - 3:53 p.m.

Improper Authentication in Apache Shiro

2021-05-0715:53:10
Google
osv.dev
21

0.016 Low

EPSS

Percentile

87.3%

Apache Shiro is a powerful and easy-to-use Java security framework that performs authentication, authorization, cryptography, and session management. Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

References