Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2010-11-05T16:28:00
Updated: 2024-08-07T03:26:11.892Z
Reserved: 2010-10-08T00:00:00
Link: CVE-2010-3863
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-11-05T17:00:02.577
Modified: 2024-11-21T01:19:46.793
Link: CVE-2010-3863
Redhat
No data.