Information on source package shiro

Available versions

ReleaseVersion
buster1.3.2-4+deb10u1
bullseye1.3.2-4+deb11u1
bookworm1.3.2-5
trixie1.3.2-5
sid1.3.2-5

Open issues

BugbusterbullseyebookwormtrixiesidDescription
CVE-2023-46750vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableURL Redirection to Untrusted Site ('Open Redirect') vulnerability when ...
CVE-2023-34478vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableApache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a ...
CVE-2023-22602vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableWhen using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, ...
CVE-2022-40664vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableApache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shi ...
CVE-2022-32532vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableApache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured ...
CVE-2021-41303vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableApache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a ...
CVE-2019-12422vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableApache Shiro before 1.4.2, when using the default "remember me" config ...

Resolved issues

BugDescription
CVE-2023-46749Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a p ...
CVE-2020-17523Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a spec ...
CVE-2020-17510Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a spec ...
CVE-2020-13933Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafte ...
CVE-2020-11989Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic ...
CVE-2020-1957Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic ...
CVE-2016-6802Apache Shiro before 1.3.2 allows attackers to bypass intended servlet ...
CVE-2016-4437Apache Shiro before 1.2.5, when a cipher key has not been configured f ...
CVE-2014-0074Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthen ...
CVE-2010-3863Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize ...

Security announcements

DSA / DLADescription
DLA-2726-1shiro - security update
DLA-2273-1shiro - security update
DLA-2181-1shiro - security update

Search for package or bug name: Reporting problems