CVE-2014-0074 PUBLISHED CVSS 7.5 HIGH

Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.

EPSS 0.27% · 50.1th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
0.27%
50.1th percentile

Affected Products

VendorProductVersions
apacheshiro1.0.0, 1.1.0, 1.2.0
n/an/an/a

Timeline

References

Open in Interactive Console →