Apache Shiro URI Path Security Directory Traversal Information Disclosure

medium Nessus Plugin ID 50600

Synopsis

A security framework running on the remote web server is affected by an information disclosure vulnerability.

Description

The version of the Apache Shiro open source security framework running on the remote web server is affected by an error in the path-based filter chain mechanism due to a failure to properly normalize URI paths before comparing them with entries in the shiro.ini file. An unauthenticated, remote attacker can exploit this, via a crafted request using directory traversal, to bypass intended access restrictions, resulting in the disclosure of sensitive information.

Solution

Upgrade to Apache Shiro version 1.1.0 or later.

See Also

http://www.nessus.org/u?03f0578a

Plugin Details

Severity: Medium

ID: 50600

File Name: shiro_slashdot_bypass.nasl

Version: 1.14

Type: remote

Family: CGI abuses

Published: 11/15/2010

Updated: 4/11/2022

Configuration: Enable paranoid mode, Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2010-3863

Vulnerability Information

CPE: cpe:/a:apache:shiro

Required KB Items: Settings/ParanoidReport

Exploit Ease: No exploit is required

Exploited by Nessus: true

Patch Publication Date: 11/3/2010

Vulnerability Publication Date: 11/3/2010

Reference Information

CVE: CVE-2010-3863

BID: 44616