CVE-2014-0074

EUVD-2014-0167
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
Affected Products (NVD)
VendorProductVersion
apacheshiro
1.0.0
apacheshiro
1.1.0
apacheshiro
1.2.0
apacheshiro
1.2.1
apacheshiro
1.2.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
shiro
bookworm
1.3.2-5
fixed
bullseye
1.3.2-4+deb11u1
fixed
sid
1.3.2-5
fixed
trixie
1.3.2-5
fixed