CVE-2023-34478: Apache Shiro

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+

Affected products

  • Apache Shiro: before 1.12.0 (fixed in 1.12.0); version 2.0.0 only

Published 2023-07-24. Last modified 2026-06-17.