Vulnerability record · CVE-2020-17523 · published 3 February 2021
CVE-2020-17523: Apache Shiro with Spring authentication bypass via crafted HTTP request
Apache · Shiro
Apache Shiro before 1.7.1, when used with Spring, can be made to bypass authentication by a specially crafted HTTP request. The flaw is an improper authentication issue (CWE-287) in the Shiro-Spring integration, and it matters because it lets an unauthenticated remote user reach protected resources.
Description
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS probability, makes this a top remediation priority despite the absence of KEV listing.
What it is
Apache Shiro before 1.7.1, when used with Spring, can be made to bypass authentication by a specially crafted HTTP request. The flaw is an improper authentication issue (CWE-287) in the Shiro-Spring integration, and it matters because it lets an unauthenticated remote user reach protected resources.
Impact
An attacker gains access to functionality that should require authentication, with the CVSS vector indicating high confidentiality, integrity and availability impact. No user interaction or prior credentials are needed.
Attack surface
Reachable over the network via HTTP against applications that combine Apache Shiro with Spring; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is very high at 0.859 (99.7th percentile), indicating strong likelihood of attempted exploitation; reference tags are limited to mailing list and vendor advisory, with no public exploit tag.
What to do
- Upgrade Apache Shiro to 1.7.1 or later, which is the fixed release named in the advisory.
- If immediate upgrade is not possible, restrict or monitor external access to Shiro-protected endpoints in Spring applications.
- Review Shiro filter chain and path-matching configuration for patterns that could be bypassed by crafted request paths.
- Confirm no Shiro version below 1.7.1 remains in dependency manifests or bundled application servers.
Detection
- Inspect HTTP access logs for requests with unusual path encodings, trailing characters or semicolons targeting Shiro-protected URLs.
- Alert on successful responses (2xx) to endpoints that should require authentication from unauthenticated sessions.
- Monitor for Shiro version strings below 1.7.1 in application inventory or dependency scans.
- Correlate anomalous request patterns with subsequent access to administrative or sensitive application functions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-17523 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-17523), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.