OSV 1.4.0 · unreviewed · 修改于 2026-09-02 02:30
发布时间
2026-08-31 17:30
GitHub 审查时间
—
NVD 发布时间
2026-08-31 16:17
源文件
advisories/unreviewed/2026/08/GHSA-r2fv-9rvj-c54c/GHSA-r2fv-9rvj-c54c.json
When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Apache Shiro versions 2.x through 3.0.0 only in deployments that use the Jakarta EE integration module.
Mitigation: Upgrade to version 3.0.1 or later, which fixes the issue. +
Alternatively, you can set the org.apache.shiro.form-resubmit-host (String) and org.apache.shiro.form-resubmit-port (Integer) system properties to restrict the host and port that Shiro will connect to when resubmitting a form.
该公告没有提供结构化的受影响软件包信息。