CVE-2021-41303: Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass
Published Sep 17, 2021
·Updated
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
Affected Software
3 affected components
Apache Shiro<1.8.0
Oracle Financial Services Crime And Compliance Management Studio=8.0.8.2.0
Oracle Financial Services Crime And Compliance Management Studio=8.0.8.3.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Shiroto a version that resolves this vulnerability.Fixed in 1.8.0
Event History
Sep 17, 2021
CVE Published
via MITRE·08:20 AM
Data Sourced
via MITRE·08:20 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
CVE-2021-41303
2
What is the severity of CVE-2021-41303?
The severity of CVE-2021-41303 is critical with a severity value of 9.8.
3
How does this vulnerability affect Apache Shiro?
This vulnerability affects Apache Shiro versions before 1.8.0 when used with Spring Boot.
4
How can I fix CVE-2021-41303?
Users should update to Apache Shiro 1.8.0 to fix this vulnerability.
5
Where can I find more information about CVE-2021-41303?
More information about CVE-2021-41303 can be found in the following references: [reference links]