Authentication Bypass in Apache Shiro 1.x
CVE-2014-0074

Currently unrated

Key Information:

Vendor

Apache

Status
Vendor
CVE Published:
6 October 2014

What is CVE-2014-0074?

Apache Shiro versions prior to 1.2.3 are susceptible to an authentication bypass issue when configured to use an LDAP server with unauthenticated bind enabled. This vulnerability permits remote attackers to bypass authentication by exploiting the system with an empty username or password. As a result, unauthorized access to the affected system may occur, potentially compromising sensitive data and undermining application security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.