Junglewise Threat Intelligence

CVE-2020-17523: Authentication bypass in Apache Shiro

CVE-2020-17523 · Severity: low · CVSS 3.1 · Published 2022-02-09

Technologies: org.apache.shiro:shiro-spring (Maven). Vendors: Maven.

Executive brief

Authentication bypass in Apache Shiro

Affected products

  • Maven org.apache.shiro:shiro-spring
  • Maven org.apache.shiro:shiro-spring-boot-starter
  • Maven org.apache.shiro:shiro-web

Related threats