Total vulnerabilities in the database
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Software | From | Fixed in |
---|---|---|
![]() |
- | 1.2.5 |
apache / aurora | 0.10.0 | 0.18.1 |
apache / shiro | - | 1.2.5 |
redhat / jboss_middleware_text-only_advisories | 1.0 | 1.0.x |
redhat / fuse | 1.0 | 1.0.x |