CVE-2026-23903
MEDIUM5.3EPSS 0.10%Apache Shiro has an Authentication Bypass
描述
Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served from a case-insensitive filesystem, such as default macOS setup, static files may be accessed by varying the case of the filename in the request. If only lower-case (common default) filters are present in Shiro, they may be bypassed this way. Shiro 2.0.7 and later has a new parameters to remediate this issue shiro.ini: filterChainResolver.caseInsensitive = true application.propertie: shiro.caseInsensitive=true Shiro 3.0.0 and later (upcoming) makes this the default.
受影響套件(2)
- Debian/shirofrom 0
- Maven/org.apache.shiro:shiro-springfrom 0, < 2.1.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2026-23903
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2026-23903
- PATCHhttps://github.com/apache/shiro
- WEBhttps://github.com/apache/shiro/commit/3b9638b957495004599aeaf24ba8949e309f26e8
- WEBhttps://lists.apache.org/thread/5jjf0hnjcol58z2m5y255c7scz1lnp8k
- WEBhttp://www.openwall.com/lists/oss-security/2026/02/08/1