CVE-2010-3863
MEDIUM severity · CVSS 5 · Path traversal
5CVSS MEDIUM
Summary
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)55%
AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://secunia.com/advisories/41989Advisory
- http://osvdb.org/69067
- http://www.securityfocus.com/archive/1/514616/100/0/threaded
- http://www.vupen.com/english/advisories/2010/2888
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62959
- http://archives.neohapsis.com/archives/fulldisclosure/2010-11/0020.htmlExploit
- http://www.securityfocus.com/bid/44616Exploit