Loading vulnerability details...
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter. This vulnerability involves weaknesses in
This critical vulnerability poses an immediate and severe threat to system security. Exploitation could lead to complete system compromise, data breach, or denial of service. Immediate action is required.
Listed in the CISA Known Exploited Vulnerabilities (KEV) catalog — confirmed exploited in the wild.
Probability of exploitation in the next 30 days · more likely than 99.8% of all CVEs.
Apply security patches to version 1.2.5 immediately
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior