Executive brief
Apache Shiro before 1.2.5 contains a vulnerability where a default or unconfigured cipher key for the 'remember me' feature allows for the execution of arbitrary code. Remote attackers can exploit this via unspecified request parameters to bypass access restrictions or achieve remote code execution.
Affected products
- Apache Shiro before 1.2.5
- Apache Aurora 0.10.0 to 0.18.1
- Red Hat Fuse 1.0
- Red Hat JBoss Middleware text-only advisories 1.0
Timeline
- 2016-06-07: disclosed: Initial public disclosure via SecurityFocus and Packet Storm
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog