PT-2026-7017 · Apache · Apache Shiro

Jesse Yang

+1

·

Publicado

2026-01-01

·

Atualizado

2026-02-09

·

CVE-2026-23903

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Shiro versions prior to 2.0.7
Description An authentication bypass issue exists in Apache Shiro. The issue relates to bypassing authentication when accessing static files on case-insensitive filesystems by varying the case of the filename in the request, if only lower-case filters are present in Shiro. The issue only affects static files.
Recommendations Upgrade to version 2.0.7, which resolves the issue. Configure filterChainResolver.caseInsensitive = true in shiro.ini. Configure shiro.caseInsensitive=true in application.properties.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23903
GHSA-C244-P6M5-VQJ6

Produtos afetados

Apache Shiro