USN-7147-1: Apache Shiro vulnerabilities
It was discovered that Apache Shiro incorrectly handled path traversal when used with other web frameworks or path rewriting. An attacker could possibly use this issue to obtain sensitive information or administrative privileges. This update provides the corresponding fix for Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2023-34478, CVE-2023-46749) It was discovered that Apache Shiro incorrectly handled web redirects when used together with the form authentication method. An attacker could possibly use this issue to perform phishing attacks. This update provides the corresponding fix for Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2023-46750) It was discovered that Apache Shiro incorrectly handled requests through servlet filtering. An attacker could possibly use this issue to obtain administrative privileges. This update provides the corresponding fix for Ubuntu 16.04 LTS. (CVE-2016-6802)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7147-1?
The severity of USN-7147-1 is high due to the potential for attackers to obtain sensitive information or administrative privileges.
How do I fix USN-7147-1?
To fix USN-7147-1, update the libshiro-java package to the recommended versions specified for your Ubuntu release.
What versions of libshiro-java are affected by USN-7147-1?
Affected versions of libshiro-java include those prior to 1.3.2-5ubuntu0.24.10.1, 1.3.2-5ubuntu0.24.04.1~esm1, and 1.2.4-1ubuntu0.1~esm2.
What products are impacted by USN-7147-1?
USN-7147-1 impacts Ubuntu products including versions 24.10, 24.04, and 16.04 that utilize the libshiro-java package.
Is there a workaround for the vulnerabilities described in USN-7147-1?
No specific workaround is mentioned for USN-7147-1; applying the security updates is the recommended approach.