#VU78805 Path traversal in Apache Shiro - CVE-2023-34478
Published: August 1, 2023
Apache Shiro
Apache Foundation
Description
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and bypass authentication process, when used together with APIs or other web frameworks that route requests based on non-normalized requests.