CVE-2020-17510: Critical severity apache shiro vulnerability
A flaw was found in Apache shiro. When using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. This highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
— Ubuntu
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-17510?
CVE-2020-17510 is a vulnerability in Apache Shiro that allows an authentication bypass when using Apache Shiro with Spring.
What is the severity of CVE-2020-17510?
CVE-2020-17510 has a severity rating of critical with a value of 9.
How can CVE-2020-17510 affect my system?
CVE-2020-17510 can impact data confidentiality, integrity, and system availability.
Which software versions are affected by CVE-2020-17510?
Apache Shiro versions up to and excluding 1.7.0 are affected by CVE-2020-17510.
How can I fix CVE-2020-17510?
To fix CVE-2020-17510, update Apache Shiro to version 1.7.0 or higher.