← Vulnerability feed

Vulnerability record · CVE-2010-3863 · published 5 November 2010

CVE-2010-3863: Apache Shiro URI path canonicalization bypasses access restrictions

Apache · Shiro

Apache Shiro before 1.1.0 and JSecurity 0.9.x compare request URIs to shiro.ini entries without canonicalizing the path first. A crafted URI such as /./account/index.jsp can therefore evade the configured path-based access rules. This matters because the filter chain that is supposed to protect restricted resources can be skipped entirely.

5.0 CVSS 2.0 Medium EPSS 55% · top 1.0% CWE-22 · Path traversal
5.0CVSS 2.0 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./account/index.jsp URI.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityThe flaw is trivially reachable without authentication, public exploit references exist, and EPSS is very high, though the direct impact is limited to partial information disclosure.

What it is

Apache Shiro before 1.1.0 and JSecurity 0.9.x compare request URIs to shiro.ini entries without canonicalizing the path first. A crafted URI such as /./account/index.jsp can therefore evade the configured path-based access rules. This matters because the filter chain that is supposed to protect restricted resources can be skipped entirely.

Impact

An attacker gains access to resources that the shiro.ini configuration intended to restrict, with the demonstrated case being read access to a protected account page. The CVSS vector indicates partial confidentiality impact only, with no integrity or availability effect.

Attack surface

Reachable remotely over the network by sending a crafted HTTP request containing a non-canonical path; the vector AV:N/AC:L/Au:N/C:P/I:N/A:N indicates no authentication and no user interaction are required.

Exploitation

Public exploit references exist (Full Disclosure and SecurityFocus BID 44616 are tagged Exploit), and EPSS is 0.54521 at the 98.965th percentile, but the CVE is not listed in CISA KEV and no ransomware use is documented.

What to do

  • Upgrade Apache Shiro to 1.1.0 or later, or migrate off JSecurity 0.9.x, which is the only complete fix.
  • If immediate upgrade is not possible, place a front-end proxy or servlet filter that normalizes and rejects non-canonical request paths before they reach Shiro.
  • Review shiro.ini filter chain definitions for path-based rules that can be bypassed by dot-segment or encoding tricks and tighten them.
  • Restrict network access to protected application paths to trusted sources as a compensating control until patching is complete.

Detection

  • Search web access logs for request URIs containing dot-segments such as /./, /../, or encoded equivalents like %2e%2e targeting protected paths.
  • Alert on requests to restricted paths that return HTTP 200 where the baseline for unauthenticated access is a redirect or 403.
  • Monitor for repeated probing of protected paths with path-manipulation variants from a single source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-3863 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4437Apache Shiro hardcoded remember-me cipher key enables code executionApache Shiro before 1.2.5 uses a default cipher key for the "remember me" feature when no key is configured, allowing attackers to forge or decrypt r…KEVEPSS 93%analysed9.8CVE-2023-34478Apache shiro path traversal vulnerabilityApache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth…EPSS 2.1%9.8CVE-2022-40664Apache shiro improper authentication vulnerabilityApache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.EPSS 2.7%9.8CVE-2022-32532Apache shiro incorrect authorization vulnerabilityApache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatch…EPSS 26%9.8CVE-2021-41303Apache Shiro with Spring Boot authentication bypass via crafted HTTP requestApache Shiro before 1.8.0, when used with Spring Boot, can be tricked by a specially crafted HTTP request into bypassing authentication. The flaw is …EPSS 77%analysed9.8CVE-2020-17523Apache Shiro with Spring authentication bypass via crafted HTTP requestApache Shiro before 1.7.1, when used with Spring, can be made to bypass authentication by a specially crafted HTTP request. The flaw is an improper a…EPSS 86%analysed9.8CVE-2020-17510Apache shiro improper authentication vulnerabilityApache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.EPSS 8.2%9.8CVE-2020-11989Apache shiro vulnerabilityApache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.EPSS 24%

Source: NIST National Vulnerability Database (record CVE-2010-3863), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.