CVE-2020-17523
CRITICALApache Shiro < 1.7.1 - Authentication Bypass via Crafted HTTP Request
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2020-17523. PoCs published by jweny, JAckLosingHeart.
AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2020-17523, an authentication bypass vulnerability in Apache Shiro versions prior to 1.7.1. The exploit demonstrates two methods to bypass authentication by manipulating URL paths with spaces or special characters.
Description
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Exploits (2)
This repository contains a proof-of-concept for CVE-2020-17523, an authentication bypass vulnerability in Apache Shiro versions prior to 1.7.1. The exploit demonstrates two methods to bypass authentication by manipulating URL paths with spaces or special characters.
This repository contains a functional proof-of-concept for CVE-2020-17523, an authentication bypass vulnerability in Apache Shiro. The exploit leverages a misconfiguration in the `RequestMappingHandlerMapping` to bypass authentication checks.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H