Vulnerability Description
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Shiro | < 1.7.0 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/r575301804bfac87a064359cf4b4ae9d514f2d10db7
- https://lists.apache.org/thread.html/r70098e336d02047ce4d4e69293fe8d558cd68cde06
- https://lists.apache.org/thread.html/r70b907ccb306e9391145e2b10f56cc6914a245f917
- https://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a
- https://lists.apache.org/thread.html/r95bdf3703858b5f958b5e190d747421771b430d970
- https://lists.apache.org/thread.html/r9d93dfb5df016b1a71a808486bc8f9fbafebbdbc85
- https://lists.apache.org/thread.html/rb47d88af224e396ee34ffb88ee99fb6d04510de572
- https://lists.apache.org/thread.html/rc2cff2538b683d480426393eecf1ce8dd80e052fbeMailing ListVendor Advisory
- https://lists.apache.org/thread.html/re25b8317b00a50272a7252c4552cf1a81a97984cc2
- https://lists.debian.org/debian-lts-announce/2021/08/msg00002.htmlMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r575301804bfac87a064359cf4b4ae9d514f2d10db7
- https://lists.apache.org/thread.html/r70098e336d02047ce4d4e69293fe8d558cd68cde06
- https://lists.apache.org/thread.html/r70b907ccb306e9391145e2b10f56cc6914a245f917
- https://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a
- https://lists.apache.org/thread.html/r95bdf3703858b5f958b5e190d747421771b430d970
FAQ
What is CVE-2020-17510?
CVE-2020-17510 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
How severe is CVE-2020-17510?
CVE-2020-17510 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-17510?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Shiro, Debian Debian Linux.