Path traversal in Apache Shiro - CVE-2023-46749

 

Path traversal in Apache Shiro - CVE-2023-46749

Published: January 14, 2024


Vulnerability identifier: #VU85349
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46749
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system. This can lead to authentication bypass when used together with path rewriting.


Affected software

Apache Shiro
Fuse

How to mitigate CVE-2023-46749

Install update from vendor's website.

Apache Shiro - update to 1.13.0
Fuse - update to 7.13.0

External References

Related Security Bulletins