https://seclists.org/oss-sec/2023/q3/62: CVE-2023-34478: Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.
Published Jul 24, 2023
·Updated
Affected Software
1 affected component
Apache Shiro<1.12.0, <2.0.0-alpha-3
Frequently Asked Questions
1
What is the severity of CVE-2023-34478?
The severity of CVE-2023-34478 is classified as important.
2
Which versions of Apache Shiro are affected by CVE-2023-34478?
CVE-2023-34478 affects Apache Shiro versions before 1.12.0 and before 2.0.0-alpha-3.
3
How do I fix CVE-2023-34478?
To fix CVE-2023-34478, upgrade Apache Shiro to version 1.12.0 or 2.0.0-alpha-3 or later.
4
What type of attack does CVE-2023-34478 allow?
CVE-2023-34478 allows for a path traversal attack that can result in authentication bypass.
5
What usage context makes CVE-2023-34478 a risk?
CVE-2023-34478 is a risk when Apache Shiro is used in conjunction with APIs or other web frameworks that route requests based on non-normalized requests.