← Vulnerability feed

Vulnerability record · CVE-2020-17523 · published 3 February 2021

CVE-2020-17523: Apache Shiro with Spring authentication bypass via crafted HTTP request

Apache · Shiro

Apache Shiro before 1.7.1, when used with Spring, can be made to bypass authentication by a specially crafted HTTP request. The flaw is an improper authentication issue (CWE-287) in the Shiro-Spring integration, and it matters because it lets an unauthenticated remote user reach protected resources.

9.8 CVSS 3.1 Critical EPSS 86% · top 0.3% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 9.0
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS probability, makes this a top remediation priority despite the absence of KEV listing.

What it is

Apache Shiro before 1.7.1, when used with Spring, can be made to bypass authentication by a specially crafted HTTP request. The flaw is an improper authentication issue (CWE-287) in the Shiro-Spring integration, and it matters because it lets an unauthenticated remote user reach protected resources.

Impact

An attacker gains access to functionality that should require authentication, with the CVSS vector indicating high confidentiality, integrity and availability impact. No user interaction or prior credentials are needed.

Attack surface

Reachable over the network via HTTP against applications that combine Apache Shiro with Spring; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is very high at 0.859 (99.7th percentile), indicating strong likelihood of attempted exploitation; reference tags are limited to mailing list and vendor advisory, with no public exploit tag.

What to do

  • Upgrade Apache Shiro to 1.7.1 or later, which is the fixed release named in the advisory.
  • If immediate upgrade is not possible, restrict or monitor external access to Shiro-protected endpoints in Spring applications.
  • Review Shiro filter chain and path-matching configuration for patterns that could be bypassed by crafted request paths.
  • Confirm no Shiro version below 1.7.1 remains in dependency manifests or bundled application servers.

Detection

  • Inspect HTTP access logs for requests with unusual path encodings, trailing characters or semicolons targeting Shiro-protected URLs.
  • Alert on successful responses (2xx) to endpoints that should require authentication from unauthenticated sessions.
  • Monitor for Shiro version strings below 1.7.1 in application inventory or dependency scans.
  • Correlate anomalous request patterns with subsequent access to administrative or sensitive application functions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://lists.apache.org/thread.html/r5b93ddf97e2c4cda779d22fab30539bdec454cfa5baec4ad0ffae235%40%3Cgitbox.activemq.apac
https://lists.apache.org/thread.html/r679ca97813384bdb1a4c087810ba44d9ad9c7c11583979bb7481d196%40%3Cdev.shiro.apache.org
https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd%40%3Cusers.activemq.apach
https://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a2a1076817390ac%40%3Cdev.shiro.apache.org
https://lists.apache.org/thread.html/r9d93dfb5df016b1a71a808486bc8f9fbafebbdbc8533625f91253f1d%40%3Cdev.shiro.apache.org
https://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/rd4b613e121438b97e3eb263cac3137caddb1dbd8f648b73a4f1898a6%40%3Cissues.activemq.apac
https://lists.apache.org/thread.html/re25b8317b00a50272a7252c4552cf1a81a97984cc2111ef7728e48e0%40%3Cdev.shiro.apache.org
https://lists.apache.org/thread.html/r5b93ddf97e2c4cda779d22fab30539bdec454cfa5baec4ad0ffae235%40%3Cgitbox.activemq.apac
https://lists.apache.org/thread.html/r679ca97813384bdb1a4c087810ba44d9ad9c7c11583979bb7481d196%40%3Cdev.shiro.apache.org
https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd%40%3Cusers.activemq.apach
https://lists.apache.org/thread.html/r852971e28f54cafa7d325bd7033115c67d613b112a2a1076817390ac%40%3Cdev.shiro.apache.org
https://lists.apache.org/thread.html/r9d93dfb5df016b1a71a808486bc8f9fbafebbdbc8533625f91253f1d%40%3Cdev.shiro.apache.org
https://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/rd4b613e121438b97e3eb263cac3137caddb1dbd8f648b73a4f1898a6%40%3Cissues.activemq.apac
https://lists.apache.org/thread.html/re25b8317b00a50272a7252c4552cf1a81a97984cc2111ef7728e48e0%40%3Cdev.shiro.apache.org

Track CVE-2020-17523 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4437Apache Shiro hardcoded remember-me cipher key enables code executionApache Shiro before 1.2.5 uses a default cipher key for the "remember me" feature when no key is configured, allowing attackers to forge or decrypt r…KEVEPSS 93%analysed9.8CVE-2023-34478Apache shiro path traversal vulnerabilityApache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth…EPSS 2.1%9.8CVE-2022-40664Apache shiro improper authentication vulnerabilityApache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.EPSS 2.7%9.8CVE-2022-32532Apache shiro incorrect authorization vulnerabilityApache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatch…EPSS 26%9.8CVE-2021-41303Apache Shiro with Spring Boot authentication bypass via crafted HTTP requestApache Shiro before 1.8.0, when used with Spring Boot, can be tricked by a specially crafted HTTP request into bypassing authentication. The flaw is …EPSS 77%analysed9.8CVE-2020-17510Apache shiro improper authentication vulnerabilityApache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.EPSS 8.2%9.8CVE-2020-11989Apache shiro vulnerabilityApache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.EPSS 24%9.8CVE-2020-1957Apache shiro vulnerabilityApache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.EPSS 23%

Source: NIST National Vulnerability Database (record CVE-2020-17523), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.