Skip to main content

Use of Hard-coded Cryptographic Key in org.apache.shiro:shiro-core

CVE-2016-4437

  • org.apache.shiro:shiro-core
  • org.apache.shiro:shiro-root
Severity High
Score 9.8/10

Summary

Apache Shiro versions prior to 1.2.5, when a cipher key has not been configured for the "remember me" feature, allow remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified "request" parameter.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-321 - Use of Hard-coded Cryptographic Key

The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.

Advisory Timeline

  • Published