Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2020-17523
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.888
EPSS Ranking
99.5%
CVSS Severity
CVSS v3 Score
9.8
CVSS v2 Score
9.0
References
https://lists.apache.org/thread.html/r5b93ddf97e2c4cda779d22fab30539bdec454cfa5baec4ad0ffae235%40%3Cgitbox.activemq.apache.org%3E
https://lists.apache.org/thread.html/r679ca97813384bdb1a4c087810ba44d9ad9c7c11583979bb7481d196%40%3Cdev.shiro.apache.org%3E
https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd%40%3Cusers.activemq.apache.org%3E
https://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a2a1076817390ac%40%3Cdev.shiro.apache.org%3E
https://lists.apache.org/thread.html/r9d93dfb5df016b1a71a808486bc8f9fbafebbdbc8533625f91253f1d%40%3Cdev.shiro.apache.org%3E
https://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org%3E
https://lists.apache.org/thread.html/rd4b613e121438b97e3eb263cac3137caddb1dbd8f648b73a4f1898a6%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/re25b8317b00a50272a7252c4552cf1a81a97984cc2111ef7728e48e0%40%3Cdev.shiro.apache.org%3E
https://lists.apache.org/thread.html/r5b93ddf97e2c4cda779d22fab30539bdec454cfa5baec4ad0ffae235%40%3Cgitbox.activemq.apache.org%3E
https://lists.apache.org/thread.html/r679ca97813384bdb1a4c087810ba44d9ad9c7c11583979bb7481d196%40%3Cdev.shiro.apache.org%3E
https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd%40%3Cusers.activemq.apache.org%3E
https://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a2a1076817390ac%40%3Cdev.shiro.apache.org%3E
https://lists.apache.org/thread.html/r9d93dfb5df016b1a71a808486bc8f9fbafebbdbc8533625f91253f1d%40%3Cdev.shiro.apache.org%3E
https://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org%3E
https://lists.apache.org/thread.html/rd4b613e121438b97e3eb263cac3137caddb1dbd8f648b73a4f1898a6%40%3Cissues.activemq.apache.org%3E
https://lists.apache.org/thread.html/re25b8317b00a50272a7252c4552cf1a81a97984cc2111ef7728e48e0%40%3Cdev.shiro.apache.org%3E
Products affected by CVE-2020-17523
Apache
»
Shiro
»
Version:
N/A
cpe:2.3:a:apache:shiro:-
Apache
»
Shiro
»
Version:
1.1.0
cpe:2.3:a:apache:shiro:1.1.0
Apache
»
Shiro
»
Version:
1.2.0
cpe:2.3:a:apache:shiro:1.2.0
Apache
»
Shiro
»
Version:
1.2.1
cpe:2.3:a:apache:shiro:1.2.1
Apache
»
Shiro
»
Version:
1.2.2
cpe:2.3:a:apache:shiro:1.2.2
Apache
»
Shiro
»
Version:
1.2.3
cpe:2.3:a:apache:shiro:1.2.3
Apache
»
Shiro
»
Version:
1.2.4
cpe:2.3:a:apache:shiro:1.2.4
Apache
»
Shiro
»
Version:
1.2.5
cpe:2.3:a:apache:shiro:1.2.5
Apache
»
Shiro
»
Version:
1.2.6
cpe:2.3:a:apache:shiro:1.2.6
Apache
»
Shiro
»
Version:
1.3.0
cpe:2.3:a:apache:shiro:1.3.0
Apache
»
Shiro
»
Version:
1.3.1
cpe:2.3:a:apache:shiro:1.3.1
Apache
»
Shiro
»
Version:
1.3.2
cpe:2.3:a:apache:shiro:1.3.2
Apache
»
Shiro
»
Version:
1.4.0
cpe:2.3:a:apache:shiro:1.4.0
Apache
»
Shiro
»
Version:
1.4.1
cpe:2.3:a:apache:shiro:1.4.1
Apache
»
Shiro
»
Version:
1.4.2
cpe:2.3:a:apache:shiro:1.4.2
Apache
»
Shiro
»
Version:
1.5.0
cpe:2.3:a:apache:shiro:1.5.0
Apache
»
Shiro
»
Version:
1.5.1
cpe:2.3:a:apache:shiro:1.5.1
Apache
»
Shiro
»
Version:
1.5.2
cpe:2.3:a:apache:shiro:1.5.2
Apache
»
Shiro
»
Version:
1.5.3
cpe:2.3:a:apache:shiro:1.5.3
Apache
»
Shiro
»
Version:
1.6.0
cpe:2.3:a:apache:shiro:1.6.0
Apache
»
Shiro
»
Version:
1.7.0
cpe:2.3:a:apache:shiro:1.7.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved