chore: upgrade org.apache.shiro:shiro-core #28
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Upgrade
org.apache.shiro:shiro-corefrom1.2.4to1.13.0This pull request upgrades
org.apache.shiro:shiro-corefrom version1.2.4to1.13.0to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.Vulnerabilities Addressed
| CVE-2023-46749 | Apache Shiro vulnerable to path traversal. Apache Shiro vulnerable to path traversal |
| CVE-2016-4437 | Improper Access Control in Apache Shiro. Improper Access Control in Apache Shiro |
| CVE-2019-12422 | Improper input validation in Apache Shiro. Improper input validation in Apache Shiro |
| CVE-2020-1957 | Improper Authentication in Apache Shiro. Improper Authentication in Apache Shiro |
| CVE-2020-11989 | Improper Authentication in Apache Shiro. Improper Authentication in Apache Shiro |
| CVE-2020-13933 | Authentication bypass in Apache Shiro. Authentication bypass in Apache Shiro |
| CVE-2021-41303 | Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass. Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass |
| CVE-2022-32532 | Improper Authorization in Apache Shiro. Improper Authorization in Apache Shiro |
This upgrade enhances the security and stability of the
org.apache.shiro:shiro-coredependency.