First published: Thu Sep 07 2023(Updated: )
It was discovered that Apache Shiro incorrectly handled certain HTTP requests. A remote attacker could possibly use this issue to bypass security restrictions. (CVE-2020-13933, CVE-2020-17510)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libshiro-java | <1.3.2-4ubuntu0.2 | 1.3.2-4ubuntu0.2 |
=20.04 | ||
All of | ||
ubuntu/libshiro-java | <1.3.2-3ubuntu0.18.04.1~esm1 | 1.3.2-3ubuntu0.18.04.1~esm1 |
=18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-6352-1 is not provided in the description.
The vulnerabilities included in USN-6352-1 are CVE-2020-13933 and CVE-2020-17510.
A remote attacker can exploit CVE-2020-13933 to bypass security restrictions.
The description does not provide details on how a remote attacker can exploit CVE-2020-17510.
To fix the Apache Shiro vulnerabilities in Ubuntu 20.04, update the libshiro-java package to version 1.3.2-4ubuntu0.2.
To fix the Apache Shiro vulnerabilities in Ubuntu 18.04, update the libshiro-java package to version 1.3.2-3ubuntu0.18.04.1~esm1.