PT-2010-5126 · Apache+1 · Apache Shiro+1
Published
2010-11-05
·
Updated
2022-05-14
·
CVE-2010-3863
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Shiro versions prior to 1.1.0
JSecurity version 0.9.x
Description
The issue allows remote attackers to bypass intended access restrictions by sending a crafted request. This is demonstrated by the "/./account/index.jsp" URI, which can be used to circumvent restrictions. The problem arises because URI paths are not properly canonicalized before being compared to entries in the shiro.ini file.
Recommendations
For Apache Shiro versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue.
For JSecurity version 0.9.x, consider disabling access to sensitive areas of the application until a patch or update is available, or apply configuration changes to restrict access to intended areas.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Shiro
Security