江南一点雨

3 exploits Active since Jun 2020
CVE-2020-11989 GITHUB CRITICAL java WORKING POC
Apache Shiro < 1.5.3 - Authentication Bypass
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
5 stars
CVSS 9.8
CVE-2020-13933 GITHUB HIGH java WORKING POC
Apache Shiro < 1.6.0 - Authentication Bypass
Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.
5 stars
CVSS 7.5
CVE-2020-11989 NOMISEC CRITICAL STUB
Apache Shiro < 1.5.3 - Authentication Bypass
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
CVSS 9.8