Vulnerability record · CVE-2021-41303 · published 17 September 2021
CVE-2021-41303: Apache Shiro with Spring Boot authentication bypass via crafted HTTP request
Apache · Shiro
Apache Shiro before 1.8.0, when used with Spring Boot, can be tricked by a specially crafted HTTP request into bypassing authentication. The flaw is rated CVSS 3.1 9.8 (critical) and affects a widely deployed Java security framework, so any exposed Shiro-protected endpoint is a candidate target. The record does not describe the exact request pattern or which Shiro/Spring Boot combinations are affected beyond the version boundary.
Description
Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, plus an EPSS probability above 0.76, makes this a top remediation priority despite no KEV listing.
What it is
Apache Shiro before 1.8.0, when used with Spring Boot, can be tricked by a specially crafted HTTP request into bypassing authentication. The flaw is rated CVSS 3.1 9.8 (critical) and affects a widely deployed Java security framework, so any exposed Shiro-protected endpoint is a candidate target. The record does not describe the exact request pattern or which Shiro/Spring Boot combinations are affected beyond the version boundary.
Impact
An unauthenticated attacker can reach protected resources without valid credentials, gaining the access level of the bypassed authentication check. Given the CVSS vector (C:H/I:H/A:H), full compromise of confidentiality, integrity and availability of the affected application is possible.
Attack surface
Reachable over the network via HTTP against a Shiro-protected Spring Boot application; the vector shows no privileges required and no user interaction. No authentication is needed to attempt the bypass.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.767, 99.5th percentile), indicating elevated likelihood of exploitation activity. Reference tags are vendor advisory, third-party advisory and patch only, with no public exploit tag supplied.
What to do
- Upgrade Apache Shiro to 1.8.0 or later, or apply the vendor patch referenced in the Oracle CPU July 2022 advisory for bundled products.
- Inventory all Spring Boot applications using Shiro and confirm the Shiro version in use, including transitive dependencies.
- Where immediate upgrade is not possible, restrict network exposure of Shiro-protected endpoints and add an upstream authentication layer.
- Review Shiro filter chain configuration for paths that may be unintentionally excluded from authentication.
- Monitor vendor advisories for NetApp and Oracle product updates that bundle the affected Shiro version.
Detection
- Search application and dependency logs for Shiro versions below 1.8.0 in Spring Boot deployments.
- Alert on HTTP requests to Shiro-protected paths that return success without a prior successful authentication event.
- Correlate access logs for unusual request patterns or path variants hitting authenticated endpoints from unauthenticated sessions.
- Monitor for anomalous access to administrative or sensitive endpoints shortly after deployment of Shiro-based services.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-41303 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-41303), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.