CVE-2020-11989 PUBLISHED

Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

EPSS 83.79% · 99.3th percentile

Risk Scores

EPSS Score
83.79%
99.3th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSshiro1.3.2-4, 0
Ubuntu:Pro:16.04:LTSshiro1.2.4-1ubuntu0.1~esm1, 1.2.4-1ubuntu0.1~esm2, 0
Ubuntu:18.04:LTSshiro1.3.2-3~18.04, 1.3.2-2, 0

Timeline

References

Open in Interactive Console →