Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2020-17523

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Attacker Value
Unknown

CVE-2020-17510

Disclosure Date: November 05, 2020 (last updated February 22, 2025)
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Attacker Value
Unknown

CVE-2020-13933

Disclosure Date: August 17, 2020 (last updated November 08, 2023)
Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.
Attacker Value
Unknown

CVE-2020-11989

Disclosure Date: June 22, 2020 (last updated November 08, 2023)
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Attacker Value
Unknown

CVE-2020-1957

Disclosure Date: March 25, 2020 (last updated November 08, 2023)
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Attacker Value
Unknown

CVE-2019-12422

Disclosure Date: November 18, 2019 (last updated November 08, 2023)
Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.
Attacker Value
Unknown

CVE-2018-20437

Disclosure Date: December 25, 2018 (last updated November 08, 2023)
An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An attacker can download a file via a request of the form /common/download?filename=1.jsp&delete=false. NOTE: the software maintainer disputes the significance of this report because the product uses a JAR archive for deployment, and this contains application.yml with configuration data
0
Attacker Value
Unknown

CVE-2016-4830

Disclosure Date: April 21, 2017 (last updated November 26, 2024)
Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates.
Attacker Value
Unknown

CVE-2016-6802

Disclosure Date: September 20, 2016 (last updated November 25, 2024)
Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
0
Attacker Value
Unknown

CVE-2014-0074

Disclosure Date: October 06, 2014 (last updated October 05, 2023)
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.
0