← Back to CVE List

CVE-2023-34478

Published: 2023-07-24T19:15Z
Last Modified: 2025-02-13T17:16Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+ > MITRE Terms of Use apply – see LICENSE‑MITRE.txt