PT-2010-5126 · Apache+1 · Apache Shiro+1

Published

2010-11-05

·

Updated

2022-05-14

·

CVE-2010-3863

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Shiro versions prior to 1.1.0 JSecurity version 0.9.x
Description The issue allows remote attackers to bypass intended access restrictions by sending a crafted request. This is demonstrated by the "/./account/index.jsp" URI, which can be used to circumvent restrictions. The problem arises because URI paths are not properly canonicalized before being compared to entries in the shiro.ini file.
Recommendations For Apache Shiro versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue. For JSecurity version 0.9.x, consider disabling access to sensitive areas of the application until a patch or update is available, or apply configuration changes to restrict access to intended areas.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3863
GHSA-3JX9-MGWX-4Q83

Affected Products

Apache Shiro
Security