Improper Authentication in Apache Shiro - CVE-2023-22602

 

Improper Authentication in Apache Shiro - CVE-2023-22602

Published: January 16, 2023


Vulnerability identifier: #VU71175
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22602
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in configuration when Shiro and Spring Boot are using different pattern-matching techniques. A remote attacker can bypass authentication process via a specially crafted HTTP request and gain unauthorized access to the application.


Affected software

Apache Shiro
Red Hat Camel for Spring Boot
Fuse
WebSphere Service Registry and Repository

How to mitigate CVE-2023-22602

Install updates from vendor's website.

Apache Shiro - update to 1.10.0
Red Hat Camel for Spring Boot - update to 3.20.1
Fuse - update to 7.12.0
WebSphere Service Registry and Repository - update to 8.5.6.3 IJ48939

External References

Related Security Bulletins