Information on source package shiro

Available versions

ReleaseVersion
stretch1.3.2-1
stretch (security)1.3.2-1+deb9u2
buster1.3.2-4
bullseye1.3.2-4
bookworm1.3.2-5
sid1.3.2-5

Open issues

BugstretchbusterbullseyebookwormsidDescription
CVE-2021-41303vulnerablevulnerablevulnerablevulnerablevulnerableApache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a ...
CVE-2020-17510fixedvulnerable (no DSA)vulnerable (no DSA)fixedfixedApache Shiro before 1.7.0, when using Apache Shiro with Spring, a spec ...
CVE-2020-13933fixedvulnerable (no DSA)vulnerable (no DSA)fixedfixedApache Shiro before 1.6.0, when using Apache Shiro, a specially crafte ...
CVE-2020-11989fixedvulnerable (no DSA)vulnerable (no DSA)fixedfixedApache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic ...
CVE-2020-1957fixedvulnerable (no DSA)vulnerable (no DSA)fixedfixedApache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic ...
CVE-2019-12422vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableApache Shiro before 1.4.2, when using the default "remember me" config ...

Resolved issues

BugDescription
CVE-2020-17523Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a spec ...
CVE-2016-6802Apache Shiro before 1.3.2 allows attackers to bypass intended servlet ...
CVE-2016-4437Apache Shiro before 1.2.5, when a cipher key has not been configured f ...
CVE-2014-0074Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthen ...
CVE-2010-3863Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize ...

Security announcements

DSA / DLADescription
DLA-2726-1shiro - security update
DLA-2273-1shiro - security update
DLA-2181-1shiro - security update

Search for package or bug name: Reporting problems