CVE-2020-17523: Critical severity apache shiro vulnerability
Published Feb 3, 2021
·Updated
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Affected Software
1 affected component
Apache Shiro<1.7.1
Event History
Feb 3, 2021
CVE Published
via MITRE·04:55 PM
Data Sourced
via MITRE·04:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-17523?
CVE-2020-17523 is a vulnerability in Apache Shiro before 1.7.1 that can bypass authentication when using Apache Shiro with Spring.
2
How severe is CVE-2020-17523?
CVE-2020-17523 has a severity of 9.8 (Critical).
3
What software is affected by CVE-2020-17523?
Apache Shiro versions up to 1.7.1 are affected by CVE-2020-17523.
4
How can I fix CVE-2020-17523?
To fix CVE-2020-17523, update Apache Shiro to version 1.7.1 or later.
5
What is the CWE of CVE-2020-17523?
CVE-2020-17523 is associated with CWE-287, which is an improper authentication vulnerability.