Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Shiro
Total 23 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13933 2 Apache, Debian 2 Shiro, Debian Linux 2024-11-21 5.0 MEDIUM 7.5 HIGH
Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.
CVE-2020-11989 1 Apache 1 Shiro 2024-11-21 7.5 HIGH 9.8 CRITICAL
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
CVE-2019-12422 1 Apache 1 Shiro 2024-11-21 5.0 MEDIUM 7.5 HIGH
Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.