PT-2016-3363 · Apache+1 · Apache Shiro+1
Published
2016-06-03
·
Updated
2025-04-03
·
CVE-2016-4437
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Shiro versions prior to 1.2.5
Description
The issue is related to the "remember me" feature in Apache Shiro, where the lack of a configured cipher key allows remote attackers to execute arbitrary code or bypass intended access restrictions. This can be achieved via an unspecified request parameter. The vulnerability is associated with the use of a default encryption key.
Recommendations
For versions prior to 1.2.5, update to version 1.2.5 or later to resolve the issue. As a temporary workaround, consider configuring a cipher key for the "remember me" feature to prevent exploitation. Restrict access to the "remember me" functionality until a patch is applied.
Exploit
Fix
RCE
Improper Access Control
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Shiro
Ubuntu