Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 16.04 LTS: USN-7139-1 critical: Apache Shiro remote access risk

Apache Shiro could be made to run programs or expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-7139-1 December 05, 2024 shiro vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Apache Shiro could be made to run programs or expose sensitive information over the network. Software Description: - shiro: Powerful and easy-to-use Java security framework Details: It was discovered that Apache Shiro used a static cipher within the "Remember Me" feature inside authentication by default. An attacker could possibly use this issue to achieve remote code execution or obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libshiro-java 1.2.4-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7139-1 CVE-2016-4437 . Uncover essential news regarding the Apache Shiro flaw impacting Ubuntu 16.04 LTS, including potential risk levels and suggested mitigation strategies.. Ubuntu, Apache Shiro, security advisory, remote access, sensitive data. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 05, 2024 Critical Ubuntu
197

Debian: DLA-2181-1 Critical: Shiro Path Traversal Authentication Bypass

It was discovered that there was a path-traversal issue in Apache Shiro, a security framework for the Java programming language. A specially-crafted request could cause an authentication bypass. . Package : shiro Version : 1.2.3-1+deb8u1 CVE ID : CVE-2020-1957 Debian Bug : #955018 It was discovered that there was a path-traversal issue in Apache Shiro, a security framework for the Java programming language. A specially-crafted request could cause an authentication bypass. For Debian 8 "Jessie", this issue has been fixed in shiro version 1.2.3-1+deb8u1. We recommend that you upgrade your shiro packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Uncover the vulnerability in Apache Shiro linked to path manipulation on Debian systems. Ensure you update your software for enhanced protection.. Apache Shiro, Debian Security, Path Traversal, Authentication Issue, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 19, 2020 Critical Debian LTS
89

Fedora 24: 2016-744df45727 Critical: Shiro Security Issue Fix

update to 1.3.2, security fix for CVE-2016-6802. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-744df45727 2016-09-22 20:29:50.108279 -------------------------------------------------------------------------------- Name : shiro Product : Fedora 24 Version : 1.3.2 Release : 1.fc24 URL : https://shiro.apache.org/ Summary : A powerful and flexible open-source security framework Description : Apache Shiro is a powerful and flexible open-source security framework that cleanly handles authentication, authorization, enterprise session management, single sign-on and cryptography services. -------------------------------------------------------------------------------- Update Information: update to 1.3.2, security fix for CVE-2016-6802 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1375884 - CVE-2016-6802 Apache Shiro: Security servlet filters bypass https://bugzilla.redhat.com/show_bug.cgi?id=1375884 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update shiro' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 24 incorporates shiro 1.3.2 to mitigate vulnerability CVE-2016-6802, reinforcing overall system security.. Fedora 24 update,shiro security fix,Apache Shiro security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 23, 2016 Critical Fedora
89

Fedora 25 Shiro Security Update: Moderate Bypass Issue Advisory

update to 1.3.2, security fix for CVE-2016-6802. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-2939d70cf4 2016-09-17 22:28:06.983159 -------------------------------------------------------------------------------- Name : shiro Product : Fedora 25 Version : 1.3.2 Release : 1.fc25 URL : https://shiro.apache.org/ Summary : A powerful and flexible open-source security framework Description : Apache Shiro is a powerful and flexible open-source security framework that cleanly handles authentication, authorization, enterprise session management, single sign-on and cryptography services. -------------------------------------------------------------------------------- Update Information: update to 1.3.2, security fix for CVE-2016-6802 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1375884 - CVE-2016-6802 Apache Shiro: Security servlet filters bypass https://bugzilla.redhat.com/show_bug.cgi?id=1375884 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update shiro' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 25 rolls out a vital patch for shiro to remediate a serious security loophole. Users should upgrade promptly.. Fedora 25, Shiro Security, Bypass Issue, Security Update, Open Source Framework. . LinuxSecurity.com Team

Calendar 2 Sep 17, 2016 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here