Uploaded image for project: 'OFBiz'
  1. OFBiz
  2. OFBIZ-1525 Issue to group security concerns
  3. OFBIZ-12839

[CVE-2023-34478] Apache Shiro, before 1.12.0, is susceptible to a path traversal attack

    XMLWordPrintableJSON

Details

    • Sub-task
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 18.12.09, Upcoming Branch, 22.01.01
    • 18.12.09, 22.01.01
    • framework
    • None
    • Bug Crush Event - 21/2/2015

    Description

      Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.
      Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+.

      Credit: Apache Shiro would like to thank swifty tk for reporting this issue.
      -The Apache Shiro Team

      Also at https://lists.apache.org/thread/jowcs5nd4tz5fxwl1mqkqnvyrwwx59qo
       
      jleroux: from the description I'm not sure OFBiz is concerned, anyway better to be safe than sorry

      Attachments

        Activity

          People

            jleroux Jacques Le Roux
            jleroux Jacques Le Roux
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: