VendorsApacheshiro2.0.0
Vulnerabilities

Apache Software Foundation Shiro 2.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-34478
Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.
Published 2023-07-24 · Modified
9.8EPSS 0.021
CVE-2023-46749
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting
Published 2024-01-15 · Modified
6.5EPSS 0.012
CVE-2023-46750
Apache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro.
Published 2023-12-14 · Modified
6.1EPSS 0.015