Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Ubuntu 7147-1: Apache Shiro Security Advisory Updates

ubuntu
Calendar Grey December 10, 2024
Scroller Ubuntu
Multiple security issues in Apache Shiro fixed. Upgrade required for Ubuntu users to eliminate risks and enhance security.
Several security issues were fixed in Apache Shiro.

Summary

Several security issues were fixed in Apache Shiro.

Software Description:

- shiro: Powerful and easy-to-use Java security framework

Details:

It was discovered that Apache Shiro incorrectly handled path traversal when

used with other web frameworks or path rewriting. An attacker could

possibly use this issue to obtain sensitive information or administrative

privileges. This update provides the corresponding fix for Ubuntu 24.04 LTS

and Ubuntu 24.10. (CVE-2023-34478, CVE-2023-46749)

It was discovered that Apache Shiro incorrectly handled web redirects when

used together with the form authentication method. An attacker could

possibly use this issue to perform phishing attacks. This update provides

the corresponding fix for Ubuntu 24.04 LTS and Ubuntu 24.10.

(CVE-2023-46750)

It was discovered that Apache Shiro incorrectly handled requests through

servlet filtering. An attacker could possibly use this issue to obtain

administrative privileges. This update prov...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
   libshiro-java                   1.3.2-5ubuntu0.24.10.1

Ubuntu 24.04 LTS
   libshiro-java                   1.3.2-5ubuntu0.24.04.1~esm1
                                   Available with Ubuntu Pro

Ubuntu 16.04 LTS
   libshiro-java                   1.2.4-1ubuntu0.1~esm2
                                   Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-7147-1

  CVE-2016-6802, CVE-2023-34478, CVE-2023-46749, CVE-2023-46750

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7147-1

Topics%20covered

Topics Covered

No topics assigned

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.