Known vulnerabilities in Apache Shiro

Software: Apache Shiro
Software CPE: cpe:2.3:a:apache_foundation:apache_shiro:*:*:*:*:*:*:*:*
Total vulnerabilities: 13
Public exploits: 5
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Shiro Apache Shiro is affected by 13 known vulnerabilities: 5 high, 7 medium, 1 low Critical High Medium Low

Vulnerabilities (13)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU85350 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-46750
CWE-601 Low
No
No
1.13.0 14.01.2024 SB2024011423
SB2024061009
SB2024062814
and 2 more
#VU85349 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-46749
CWE-22 Medium
No
No
1.13.0 14.01.2024 SB2024011423
SB2024061883
#VU78805 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-34478
CWE-22 High
No
No
1.12.0 01.08.2023 SB2023080109
SB2023111053
SB2023111054
and 6 more
#VU71175 - Improper Authentication
CVE-2023-22602
CWE-287 Medium
No
No
1.10.0 16.01.2023 SB2023011604
SB2023050803
SB2024030809
and 1 more
#VU68270 - Improper Authentication
CVE-2022-40664
CWE-287 High
Available
No
1.10.0 12.10.2022 SB2022101258
SB2023011226
SB2023011842
and 3 more
#VU64770 - Improper Authentication
CVE-2022-32532
CWE-287 Medium
Available
No
1.9.1 29.06.2022 SB2022062909
SB2022092661
SB2022102035
and 2 more
#VU56683 - Improper Authentication
CVE-2021-41303
CWE-287 High
No
No
1.8.0 17.09.2021 SB2021091709
SB2022072013
SB2023010505
#VU50177 - Improper Authentication
CVE-2020-17523
CWE-287 High
Available
No
1.7.1 01.02.2021 SB2021020126
SB2022091313
#VU48197 - Improper Authentication
CVE-2020-17510
CWE-287 High
No
No
1.7.0 05.11.2020 SB2020110614
SB2022091313
SB2023090702
#VU45757 - Improper Authentication
CVE-2020-13933
CWE-287 Medium
Available
No
1.6.0 18.08.2020 SB2020081810
SB2022091313
SB2022102629
and 2 more
#VU45756 - Improper Authentication
CVE-2020-11989
CWE-287 Medium
Available
No
1.5.3 18.08.2020 SB2020062233
SB2021021824
SB2022091313
#VU26475 - Improper Authentication
CVE-2020-1957
CWE-287 Medium
No
No
1.5.2 31.03.2020 SB2020033112
SB2021021824
SB2022091313
#VU22836 - Cryptographic Issues
CVE-2019-12422
CWE-310 Medium
No
No
1.4.2 19.11.2019 SB2019111908
SB2020032701
SB2022091313