pkg:Debian/shiro
22 total CVEsCRITICAL10HIGH5MEDIUM5LOW1
✅ Check your installed version
All known vulnerabilities
- from 0, < 1.2.5-1
- from 0
- from 0
- from 0
- CRITICAL9.8CVE-2021-41303Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypassfrom 0
- from 0, < 1.2.3-1+deb8u1
- from 0, < 1.3.2-4+deb11u1
- from 0, < 1.3.2-4+deb11u1
- from 0, < 1.3.2-1+deb9u1
- from 0, < 1.3.2-4+deb11u1
- from 0
- from 0, < 1.3.2-1
- from 0, < 1.3.2-1+deb9u2
- from 0, < 1.3.2-4+deb11u1
- from 0
- MEDIUM6.5CVE-2026-43828Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute.from 0
- MEDIUM6.5CVE-2026-43827Default configurations of Apache Shiro have a session fixation vulnerability.from 0
- from 0, < 1.3.2-4+deb11u1
- from 0
- from 0
- from 0
- —CVE-2014-0074Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authenticatio…from 0, < 1.2.3-1