First published: Fri Sep 17 2021(Updated: )
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Shiro | <1.8.0 | |
Oracle Financial Services Crime and Compliance Management Studio | =8.0.8.2.0 | |
Oracle Financial Services Crime and Compliance Management Studio | =8.0.8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41303
The severity of CVE-2021-41303 is critical with a severity value of 9.8.
This vulnerability affects Apache Shiro versions before 1.8.0 when used with Spring Boot.
Users should update to Apache Shiro 1.8.0 to fix this vulnerability.
More information about CVE-2021-41303 can be found in the following references: [reference links]