pkg:Debian/shiro

22 total CVEsCRITICAL10HIGH5MEDIUM5LOW1

✅ Check your installed version

All known vulnerabilities

  • CRITICAL9.8CVE-2016-4437⚠ KEVImproper Access Control in Apache Shiro
    from 0, < 1.2.5-1
  • CRITICAL9.8CVE-2023-34478Path Traversal in Apache Shiro
    from 0
  • CRITICAL9.8CVE-2022-40664Apache Shiro Authentication Bypass vulnerability
    from 0
  • CRITICAL9.8CVE-2022-32532Improper Authorization in Apache Shiro
    from 0
  • CRITICAL9.8CVE-2021-41303Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
    from 0
  • CRITICAL9.8CVE-2020-1957shiro - security update
    from 0, < 1.2.3-1+deb8u1
  • CRITICAL9.8CVE-2020-1957shiro - security update
    from 0, < 1.3.2-4+deb11u1
  • CRITICAL9.8CVE-2020-11989shiro - security update
    from 0, < 1.3.2-4+deb11u1
  • CRITICAL9.8CVE-2020-11989shiro - security update
    from 0, < 1.3.2-1+deb9u1
  • CRITICAL9.8CVE-2020-17510Authentication bypass in Apache Shiro
    from 0, < 1.3.2-4+deb11u1
  • HIGH7.5CVE-2023-22602Apache Shiro Interpretation Conflict vulnerability
    from 0
  • HIGH7.5CVE-2016-6802Improper Access Control in Apache Shiro
    from 0, < 1.3.2-1
  • HIGH7.5CVE-2020-13933shiro - security update
    from 0, < 1.3.2-1+deb9u2
  • HIGH7.5CVE-2020-13933shiro - security update
    from 0, < 1.3.2-4+deb11u1
  • HIGH7.5CVE-2019-12422Improper input validation in Apache Shiro
    from 0
  • MEDIUM6.5CVE-2026-43828Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute.
    from 0
  • MEDIUM6.5CVE-2026-43827Default configurations of Apache Shiro have a session fixation vulnerability.
    from 0
  • MEDIUM6.5CVE-2023-46749Apache Shiro vulnerable to path traversal
    from 0, < 1.3.2-4+deb11u1
  • MEDIUM6.1CVE-2023-46750Open redirect in Apache Shiro
    from 0
  • MEDIUM5.3CVE-2026-23903Apache Shiro has an Authentication Bypass
    from 0
  • LOW2.5CVE-2026-23901Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability
    from 0
  • CVE-2014-0074Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authenticatio…
    from 0, < 1.2.3-1