VDB
BDU%3A2021-05609
BDU%3A2021-05609
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Уязвимость реализации функции «Remember Me» фреймворка Apache Shiro, позволяющая нарушителю выполнить произвольный код или обойти ограничения безопасности
Risk Scores
CVSS 2.0
9.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Apache Software Foundation | Red Hat JBoss Fuse, Red Hat JBoss A-MQ, Red Hat JBoss Fuse Service Works, Shiro, Red Hat OpenShift Enterprise |
Timeline
- Nov 25, 2021 CVE Published
References
- http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html url
- http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html url
- http://www.securityfocus.com/archive/1/538570/100/0/threaded url
- http://www.securityfocus.com/bid/91024 url
- https://lists.apache.org/thread/g9kl6hgl8m6mxkc76hpvt8xg6qgkwytv url
- https://access.redhat.com/security/cve/cve-2016-4437 url
- https://www.exploit-db.com/exploits/48410 url