Vulnerability Description
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+, or ensure `blockSemicolon` is enabled (this is the default).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Shiro | < 1.13.0 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/mdv7ftz7k4488rzloxo2fb0p9shnp9wmMailing ListVendor Advisory
- https://lists.apache.org/thread/mdv7ftz7k4488rzloxo2fb0p9shnp9wmMailing ListVendor Advisory
- https://security.netapp.com/advisory/ntap-20241108-0002/
FAQ
What is CVE-2023-46749?
CVE-2023-46749 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting Mitigation: Update to Apach...
How severe is CVE-2023-46749?
CVE-2023-46749 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46749?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Shiro.