https://seclists.org/oss-sec/2024/q1/19: CVE-2023-46749: Apache Shiro before 1.130 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting
Published Jan 12, 2024
·Updated
Affected Software
1 affected component
Apache Shiro<1.130, <2.0.0-alpha-4
Frequently Asked Questions
1
What is the severity of CVE-2023-46749?
CVE-2023-46749 is considered a critical vulnerability due to its potential to allow authentication bypass.
2
How do I fix CVE-2023-46749?
To fix CVE-2023-46749, upgrade Apache Shiro to version 1.130 or 2.0.0-alpha-4 or later.
3
What versions of Apache Shiro are affected by CVE-2023-46749?
CVE-2023-46749 affects all versions of Apache Shiro prior to 1.130 and 2.0.0-alpha-4.
4
What type of attack does CVE-2023-46749 exploit?
CVE-2023-46749 exploits a path traversal attack that can lead to an authentication bypass.
5
In what context does CVE-2023-46749 pose a risk?
CVE-2023-46749 poses a risk when Apache Shiro is used with path rewriting techniques.