CVE-2014-0074: High severity apache shiro vulnerability
Published Oct 6, 2014
·Updated
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.
Affected Software
5 affected components
Apache Shiro=1.0.0
Apache Shiro=1.1.0
Apache Shiro=1.2.0
Apache Shiro=1.2.1
Apache Shiro=1.2.2
Event History
Oct 6, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0074?
CVE-2014-0074 is considered a high severity vulnerability due to its ability to allow unauthenticated access to sensitive information.
2
How do I fix CVE-2014-0074?
To fix CVE-2014-0074, upgrade to Apache Shiro version 1.2.3 or higher where the vulnerability is patched.
3
Which versions of Apache Shiro are affected by CVE-2014-0074?
CVE-2014-0074 affects Apache Shiro versions 1.0.0 through 1.2.2.
4
What type of attack does CVE-2014-0074 facilitate?
CVE-2014-0074 facilitates unauthorized authentication bypass through unauthenticated LDAP binds.
5
Can CVE-2014-0074 be exploited remotely?
Yes, CVE-2014-0074 can be exploited remotely by attackers targeting vulnerable Apache Shiro installations.