CVE-2019-12422: Input Validation
Published Nov 18, 2019
·Updated
Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.
Affected Software
2 affected componentsFixes available
Apache Shiro<1.4.2
redhat/shiro<1.4.2
1.4.2
Remediation
Event History
Nov 18, 2019
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-12422.
2
What is the title of the vulnerability?
The title of the vulnerability is Apache Shiro before 1.4.2 when using the default remember me configuration cookies could be susceptible to a padding attack.
3
What is the severity of CVE-2019-12422?
The severity of CVE-2019-12422 is high (7.4).
4
Which software is affected by CVE-2019-12422?
Apache Shiro versions up to but not including 1.4.2 are affected.
5
How can I fix CVE-2019-12422?
To fix CVE-2019-12422, update Apache Shiro to version 1.4.2 or later.