296,733
Total vulnerabilities in the database
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
| Software | From | Fixed in |
|---|---|---|
org.apache.shiro / shiro-core
|
- | 1.2.5 |
| apache / aurora | 0.10.0 | 0.18.1 |
| apache / shiro | - | 1.2.5 |
| redhat / jboss_middleware_text-only_advisories | 1.0 | 1.0.x |
| redhat / fuse | 1.0 | 1.0.x |