CVE-2020-13933: Input Validation
A flaw was found in Apache Shiro in versions prior to 1.6.0. A specially crafted HTTP request may cause an authentication bypass. The highest threat from this vulnerability is to data confidentiality.
Other sources
Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.
— Ubuntu
Apache Shiro could allow a remote attacker to bypass security restrictions, caused by improper authentication validation. By sending a specially-crafted HTTP request, an attacker could exploit this vulnerability to bypass access restrictions.
— IBM
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-13933?
CVE-2020-13933 is a vulnerability that affects Apache Shiro before version 1.6.0.
What is the severity of CVE-2020-13933?
The severity of CVE-2020-13933 is high with a severity value of 7.
How does CVE-2020-13933 affect Apache Shiro?
CVE-2020-13933 can potentially cause an authentication bypass when a specially crafted HTTP request is used.
Which versions of Apache Shiro are affected by CVE-2020-13933?
Versions of Apache Shiro prior to 1.6.0 are affected by CVE-2020-13933.
Are there any remedies available for CVE-2020-13933?
Yes, the remedy for CVE-2020-13933 is to update to Apache Shiro version 1.6.0 or higher.