Vulnerability Description
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
CVSS Score
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Shiro | < 1.7.1 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/r5b93ddf97e2c4cda779d22fab30539bdec454cfa5b
- https://lists.apache.org/thread.html/r679ca97813384bdb1a4c087810ba44d9ad9c7c1158
- https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae
- https://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a
- https://lists.apache.org/thread.html/r9d93dfb5df016b1a71a808486bc8f9fbafebbdbc85
- https://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/rd4b613e121438b97e3eb263cac3137caddb1dbd8f6
- https://lists.apache.org/thread.html/re25b8317b00a50272a7252c4552cf1a81a97984cc2
- https://lists.apache.org/thread.html/r5b93ddf97e2c4cda779d22fab30539bdec454cfa5b
- https://lists.apache.org/thread.html/r679ca97813384bdb1a4c087810ba44d9ad9c7c1158
- https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae
- https://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a
- https://lists.apache.org/thread.html/r9d93dfb5df016b1a71a808486bc8f9fbafebbdbc85
- https://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/rd4b613e121438b97e3eb263cac3137caddb1dbd8f6
FAQ
What is CVE-2020-17523?
CVE-2020-17523 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
How severe is CVE-2020-17523?
CVE-2020-17523 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-17523?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Shiro.