Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
2016-06-07T14:06:13.247
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | aurora | < 0.18.1 | Yes |
Application | apache | shiro | < 1.2.5 | Yes |
Application | redhat | fuse | 1.0 | Yes |
Application | redhat | jboss_middleware_text-only_advisories | 1.0 | Yes |