CVE-2020-11989
- EPSS 77.78%
- Published 22.06.2020 19:15:10
- Last modified 21.11.2024 04:59:03
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
CVE-2020-1957
- EPSS 86.1%
- Published 25.03.2020 16:15:19
- Last modified 21.11.2024 05:11:44
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
CVE-2019-12422
- EPSS 60.86%
- Published 18.11.2019 23:15:11
- Last modified 21.11.2024 04:22:48
Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.
CVE-2016-6802
- EPSS 9.91%
- Published 20.09.2016 19:59:00
- Last modified 12.04.2025 10:46:40
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
CVE-2016-4437
- EPSS 94.3%
- Published 07.06.2016 14:06:13
- Last modified 12.04.2025 10:46:40
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
CVE-2014-0074
- EPSS 0.27%
- Published 06.10.2014 14:55:08
- Last modified 12.04.2025 10:46:40
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.
- EPSS 13.4%
- Published 05.11.2010 17:00:02
- Last modified 11.04.2025 00:51:21
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the...