Skip to content

Conversation

@00felix-app
Copy link

@00felix-app 00felix-app bot commented Oct 16, 2025

Upgrade org.apache.shiro:shiro-core from 1.2.4 to 1.13.0

This pull request upgrades org.apache.shiro:shiro-core from version 1.2.4 to 1.13.0 to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.
Vulnerabilities Addressed

Vulnerability Description
CVE-2022-40664 Apache Shiro Authentication Bypass vulnerability. Apache Shiro Authentication Bypass vulnerability

| CVE-2023-46749 | Apache Shiro vulnerable to path traversal. Apache Shiro vulnerable to path traversal |

| CVE-2016-4437 | Improper Access Control in Apache Shiro. Improper Access Control in Apache Shiro |

| CVE-2019-12422 | Improper input validation in Apache Shiro. Improper input validation in Apache Shiro |

| CVE-2020-1957 | Improper Authentication in Apache Shiro. Improper Authentication in Apache Shiro |

| CVE-2020-11989 | Improper Authentication in Apache Shiro. Improper Authentication in Apache Shiro |

| CVE-2020-13933 | Authentication bypass in Apache Shiro. Authentication bypass in Apache Shiro |

| CVE-2021-41303 | Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass. Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass |

| CVE-2022-32532 | Improper Authorization in Apache Shiro. Improper Authorization in Apache Shiro |

This upgrade enhances the security and stability of the org.apache.shiro:shiro-core dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant