Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Swifty Tk

#24423de 53,639
9.8CVSS total
Vulnerabilidades · 1
PT-2023-4009
9.8
2023-06-07
Apache · Apache Shiro · CVE-2023-34478
**Name of the Vulnerable Software and Affected Versions** Apache Shiro versions prior to 1.12.0 or 2.0.0-alpha-3 **Description** The issue is related to a path traversal attack that can result in an authentication bypass when Apache Shiro is used together with APIs or other web frameworks that route requests based on non-normalized requests. This can allow a remote attacker to bypass security restrictions by sending specially crafted requests. **Recommendations** Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+ to resolve the issue.