vendor:
Shiro
by:
L / l-codes[at]qq.com
8.1
CVSS
HIGH
Arbitrary code execution
94
CWE
Product Name: Shiro
Affected Version From: 1.2.2004
Affected Version To: 1.2.2004
Patch Exists: YES
Related CWE: CVE-2016-4437
CPE: a:apache:shiro:1.2.4
Tags: cve,apache,rce,kev,packetstorm,cve2016,shiro,deserialization,oast
CVSS Metrics: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei References:
https://github.com/Medicean/VulApps/tree/master/s/shiro/1, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4437, http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html, http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html, http://rhn.redhat.com/errata/RHSA-2016-2035.html
Nuclei Metadata: {'max-request': 1, 'vendor': 'apache', 'product': 'shiro'}
Platforms Tested: Windows, Unix
2016
Apache Shiro v1.2.4 Cookie RememberME Deserial RCE
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apache Shiro v1.2.4.
Mitigation:
Apply the latest security patches and updates from the vendor.