Use of Hard-coded Cryptographic Key in org.apache.shiro:shiro-core
CVE-2016-4437
- org.apache.shiro:shiro-core
- org.apache.shiro:shiro-root
Summary
Apache Shiro versions prior to 1.2.5, when a cipher key has not been configured for the "remember me" feature, allow remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified "request" parameter.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-321 - Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
References
Advisory Timeline
- Published