USN-6352-1: Apache Shiro vulnerabilities
It was discovered that Apache Shiro incorrectly handled certain HTTP requests. A remote attacker could possibly use this issue to bypass security restrictions. (CVE-2020-13933, CVE-2020-17510)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6352-1?
The severity of USN-6352-1 is not provided in the description.
What are the vulnerabilities included in USN-6352-1?
The vulnerabilities included in USN-6352-1 are CVE-2020-13933 and CVE-2020-17510.
How can a remote attacker exploit CVE-2020-13933?
A remote attacker can exploit CVE-2020-13933 to bypass security restrictions.
How can a remote attacker exploit CVE-2020-17510?
The description does not provide details on how a remote attacker can exploit CVE-2020-17510.
How can I fix the Apache Shiro vulnerabilities in Ubuntu 20.04?
To fix the Apache Shiro vulnerabilities in Ubuntu 20.04, update the libshiro-java package to version 1.3.2-4ubuntu0.2.
How can I fix the Apache Shiro vulnerabilities in Ubuntu 18.04?
To fix the Apache Shiro vulnerabilities in Ubuntu 18.04, update the libshiro-java package to version 1.3.2-3ubuntu0.18.04.1~esm1.