CVE-2020-17523
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
- Affected products
- Apache Shiro
- Apache Shiro
- < 1.7.1
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 85.9% (100th percentile)
- Weakness
- CWE-287
- NVD status
- Modified
- Published
- 2021-02-03
CVE-2020-17523 at NVD
3 known exploits for CVE-2020-17523
Proof-of-concept code and exploit modules indexed by Sploitus