icon

We found results for “

CVE-2020-1957

Date: March 25, 2020

Overview

Apache Shiro is an open source Java security framework that provides several powerful features for securing applications, including authentication, authorization, session management, and cryptography. Affected versions of this software allow an attacker to circumvent the secure authentication process.

Details

The CVE-2020-1957 vulnerability occurs because of an authentication bypass flaw when using Apache Shiro with Spring dynamic controllers. A remote attacker can create a malicious request that causes an authentication bypass, potentially affecting data confidentiality, integrity, and system availability.

Affected Environments

Apache Shiro versions before 1.5.2

Remediation

Install the provided software updates

Prevention

Update to Apache Shiro version 1.5.2 or higher

Language: Java

Good to know:

icon
icon

Authentication Issues

CWE-287

Insufficient Information

NVD-CWE-noinfo
icon

Upgrade Version

Upgrade to version org.apache.shiro:shiro-web:1.5.2

Learn More

Base Score:
Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope (S): Unchanged
Confidentiality (C): High
Integrity (I): High
Availability (A): High
Base Score:
Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (AU): None
Confidentiality (C): Partial
Integrity (I): Partial
Availability (A): Partial
Additional information: