Apache Shiro could be made to run programs or expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-7139-1 December 05, 2024 shiro vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Apache Shiro could be made to run programs or expose sensitive information over the network. Software Description: - shiro: Powerful and easy-to-use Java security framework Details: It was discovered that Apache Shiro used a static cipher within the "Remember Me" feature inside authentication by default. An attacker could possibly use this issue to achieve remote code execution or obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libshiro-java 1.2.4-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7139-1 CVE-2016-4437 . Uncover essential news regarding the Apache Shiro flaw impacting Ubuntu 16.04 LTS, including potential risk levels and suggested mitigation strategies.. Ubuntu, Apache Shiro, security advisory, remote access, sensitive data. . Severity: Critical. LinuxSecurity.com Team
It was discovered that there was a path-traversal issue in Apache Shiro, a security framework for the Java programming language. A specially-crafted request could cause an authentication bypass. . Package : shiro Version : 1.2.3-1+deb8u1 CVE ID : CVE-2020-1957 Debian Bug : #955018 It was discovered that there was a path-traversal issue in Apache Shiro, a security framework for the Java programming language. A specially-crafted request could cause an authentication bypass. For Debian 8 "Jessie", this issue has been fixed in shiro version 1.2.3-1+deb8u1. We recommend that you upgrade your shiro packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Regards, - -- ,'`. : :' : Chris Lamb `. `'`
update to 1.3.2, security fix for CVE-2016-6802. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-744df45727 2016-09-22 20:29:50.108279 -------------------------------------------------------------------------------- Name : shiro Product : Fedora 24 Version : 1.3.2 Release : 1.fc24 URL : https://shiro.apache.org/ Summary : A powerful and flexible open-source security framework Description : Apache Shiro is a powerful and flexible open-source security framework that cleanly handles authentication, authorization, enterprise session management, single sign-on and cryptography services. -------------------------------------------------------------------------------- Update Information: update to 1.3.2, security fix for CVE-2016-6802 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1375884 - CVE-2016-6802 Apache Shiro: Security servlet filters bypass https://bugzilla.redhat.com/show_bug.cgi?id=1375884 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update shiro' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
update to 1.3.2, security fix for CVE-2016-6802. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-2939d70cf4 2016-09-17 22:28:06.983159 -------------------------------------------------------------------------------- Name : shiro Product : Fedora 25 Version : 1.3.2 Release : 1.fc25 URL : https://shiro.apache.org/ Summary : A powerful and flexible open-source security framework Description : Apache Shiro is a powerful and flexible open-source security framework that cleanly handles authentication, authorization, enterprise session management, single sign-on and cryptography services. -------------------------------------------------------------------------------- Update Information: update to 1.3.2, security fix for CVE-2016-6802 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1375884 - CVE-2016-6802 Apache Shiro: Security servlet filters bypass https://bugzilla.redhat.com/show_bug.cgi?id=1375884 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update shiro' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.