#VU50177 Improper Authentication in Apache Shiro - CVE-2020-17523
Published: February 1, 2021 / Updated: February 4, 2021
Apache Shiro
Apache Foundation
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests in Apache Shiro with Spring. A remote attacker can send a specially crafted HTTP request to bypass authentication process and gain unauthorized access to the application.