CVE-2020-13933

HIGH

Apache Shiro < 1.6.0 - Authentication Bypass

Title source: rule

Description

Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.

Exploits (5)

nomisec WORKING POC 14 stars
by EXP-Docs · poc
https://github.com/EXP-Docs/CVE-2020-13933
github WORKING POC 5 stars
by JAckLosingHeart · javapoc
https://github.com/JAckLosingHeart/CVE-PoC-Collection/tree/main/shiro-CVE-2020-13933
nomisec WRITEUP 2 stars
by 0xkami · poc
https://github.com/0xkami/cve-2020-13933
inthewild WORKING POC
poc
https://github.com/lyy289065406/cve-2020-13933

References (16)

Scores

CVSS v3 7.5
EPSS 0.6949
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (3)
apache/shiro < 1.6.0
debian/debian_linux 9.0
org.apache.shiro/shiro-core 0 - 1.6.0Maven
Published Aug 17, 2020
Tracked Since Feb 18, 2026