CVE-2020-1957: Critical severity Apache Shiro vulnerability
Published Mar 25, 2020
·Updated
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Affected Software
2 affected components
Apache Shiro<1.5.2
Debian Debian Linux=8.0
Remediation
Event History
Mar 25, 2020
CVE Published
via MITRE·03:24 PM
Data Sourced
via MITRE·03:24 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-1957?
CVE-2020-1957 is a vulnerability in Apache Shiro before 1.5.2 that allows for an authentication bypass when using Apache Shiro with Spring dynamic controllers.
2
What is the severity of CVE-2020-1957?
The severity of CVE-2020-1957 is critical, with a CVSS score of 9.8.
3
Which software versions are affected by CVE-2020-1957?
Apache Shiro versions up to but excluding 1.5.2 are affected, as well as Debian Debian Linux version 8.0.
4
How can CVE-2020-1957 be exploited?
CVE-2020-1957 can be exploited by sending a specially crafted request to the Spring dynamic controllers.
5
Where can I find more information about CVE-2020-1957?
You can find more information about CVE-2020-1957 at the following references: [link1], [link2], [link3].