First published: Wed Feb 03 2021(Updated: )
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Shiro | <1.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17523 is a vulnerability in Apache Shiro before 1.7.1 that can bypass authentication when using Apache Shiro with Spring.
CVE-2020-17523 has a severity of 9.8 (Critical).
Apache Shiro versions up to 1.7.1 are affected by CVE-2020-17523.
To fix CVE-2020-17523, update Apache Shiro to version 1.7.1 or later.
CVE-2020-17523 is associated with CWE-287, which is an improper authentication vulnerability.