CVE-2016-6802: High severity apache shiro vulnerability
Published Sep 20, 2016
·Updated
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
Affected Software
2 affected componentsFixes available
Apache Shiro=1.3.1
debian/shiro
1.3.2-4+deb11u11.3.2-5
Event History
Sep 20, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Dec 10, 2024
Data Sourced
via Launchpad·08:12 PM
Description
Dec 14, 2024
Data Sourced
via Ubuntu·08:11 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6802?
CVE-2016-6802 is classified as a Medium severity vulnerability.
2
How do I fix CVE-2016-6802?
To fix CVE-2016-6802, upgrade Apache Shiro to version 1.3.2 or later.
3
What impact does CVE-2016-6802 have on security?
CVE-2016-6802 allows attackers to bypass servlet filters, potentially granting unauthorized access to protected resources.
4
What versions of Apache Shiro are affected by CVE-2016-6802?
Apache Shiro versions prior to 1.3.2, specifically 1.3.1, are affected by CVE-2016-6802.
5
Is CVE-2016-6802 exploitable in all configurations?
CVE-2016-6802 can be exploited when a non-root servlet context path is used in the configuration.