← Back to browse · API

CVE-2023-34478

Severity
CRITICAL
CVSS
9.8
EPSS
0.02057
Risk score
39.92
CISA KEV
No
PoC
Yes
Published
2023-07-24
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2023-2115, GHSA-PMHC-2G4F-85CG
Products
Apache Software Foundation:Apache Shiro 0 <1.12.0, Apache Software Foundation:Apache Shiro 0 <2.0.0-alpha-3
Sources
euvd EUVD-2023-2115
github f876394cf4de6e693b971660|CVE-2023-34478

Description

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+

References