VendorsApacheauroraall versions
Vulnerabilities

Apache Software Foundation Aurora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2016-4437
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Published 2016-06-07 · Analyzed
9.8KEV1 PoCEPSS 0.930
CVE-2024-27905
Apache Aurora: padding oracle can allow construction an authentication cookie
Published 2024-02-27 · Analyzed
9.1EPSS 0.015