Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
| Score | Percentile |
|---|---|
| 1.80% | 82.52% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 9.8 | 3.1 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-7cj4-gj8m-m2f7 ↗ |
| CVE | CVE-2020-17510 ↗ |
| CWE id | Name |
|---|---|
| CWE-287 | Improper Authentication |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| maven | org.apache.shiro:shiro-spring | < 1.7.0 | 1.7.0 | — |