CVE-2010-3863
Apache Shiro Path Traversal vulnerability
EPSS 54.8%
描述
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
如何修補 CVE-2010-3863
要修補 CVE-2010-3863,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.shiro:shiro-root—升級至 1.1.0 或更新版本
CVE-2010-3863 正在被利用嗎?
可能 — EPSS 為 54.8%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 1.1.0