Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.
Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | no-fix-debian-deb-package | May 15, 2025 | Jul 24, 2023 | |
| Dell Powerstore Dsa2024158 | dell-powerstoreos-upgrade-latest | Jan 13, 2026 | Apr 4, 2024 | |
| Dell Powerstore Dsa2024225 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | May 29, 2024 | |
| Dell Powerstore Dsa2024287 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Jul 2, 2024 | |
| Ubuntu | ubuntu-pro-upgrade-libshiro-javaubuntu-upgrade-libshiro-java | Dec 11, 2024 | Jul 24, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub